2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32151MEDIUM5.9User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ...
CVE-2024-29978MEDIUM5.9User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ...
CVE-2024-29146MEDIUM5.9User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ...
CVE-2024-28955MEDIUM5.9Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the ...
CVE-2024-28038CRITICAL9The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More ...
CVE-2024-11202MEDIUM6.1Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in v...
CVE-2024-6749MEDIUM6.3Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may exp...
CVE-2024-6476MEDIUM4.2Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user ...
CVE-2024-11002MEDIUM6.3The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_sh...
CVE-2024-10857MEDIUM6.5The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to...
CVE-2024-10781HIGH7.5The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi...
CVE-2024-10570HIGH7.5The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an auth...
CVE-2024-10542HIGH7.5The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi...
CVE-2024-10471MEDIUM4.8The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-53278MEDIUM4.8Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin us...
CVE-2024-49353MEDIUM5.9IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to re...
CVE-2024-49351MEDIUM5.5IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user.
CVE-2024-11418MEDIUM6.1The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2024-11342MEDIUM6.1The Skt NURCaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2024-49597HIGH7.2Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Atte...
CVE-2024-49596MEDIUM6.5Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged ...
CVE-2024-49595MEDIUM4.9Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability...
CVE-2024-11678MEDIUM5.4A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnera...
CVE-2024-11677MEDIUM5.4A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affec...
CVE-2024-10729HIGH8.8The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now