2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50359HIGH7.2A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff...
CVE-2024-50358HIGH7.2A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactur...
CVE-2024-11024CRITICAL9.8The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in...
CVE-2024-10579MEDIUM4.3The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access ...
CVE-2024-10308MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdow...
CVE-2024-11680CRITICAL9.8ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated at...
CVE-2024-11032MEDIUM6.1The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg with...
CVE-2024-9170MEDIUM4.8The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_produ...
CVE-2024-11192MEDIUM6.4The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-11119MEDIUM6.4The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' sh...
CVE-2024-11091MEDIUM6.4The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-9504HIGH7.2The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via S...
CVE-2024-8772MEDIUM4.351l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable ...
CVE-2024-8160LOW2.7Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficie...
CVE-2024-6831MEDIUM4.4Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove vie...
CVE-2024-47257HIGH7.5Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead...
CVE-2024-36254HIGH7.5Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction pr...
CVE-2024-36251HIGH7.5The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More...
CVE-2024-36249HIGH7.4Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction...
CVE-2024-36248CRITICAL9.1API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model...
CVE-2024-35244CRITICAL9.1There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their ...
CVE-2024-34162MEDIUM5.3The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But co...
CVE-2024-33616MEDIUM5.3Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrat...
CVE-2024-33610CRITICAL9.1"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides log...
CVE-2024-33605HIGH7.5Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now