2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8735MEDIUM6.1The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use...
CVE-2024-11601HIGH8.1The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider...
CVE-2024-11381MEDIUM6.4The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' short...
CVE-2024-11355MEDIUM4.3The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data ...
CVE-2024-11225MEDIUM6.1The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripti...
CVE-2024-11104HIGH8.1The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider...
CVE-2024-10666MEDIUM4.3The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all ve...
CVE-2024-10034MEDIUM5.5The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga...
CVE-2024-38296MEDIUM4.4Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain ...
CVE-2024-47142MEDIUM5.5AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue wi...
CVE-2024-45837MEDIUM5.4Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A networ...
CVE-2024-39290MEDIUM6.5Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticate...
CVE-2024-31408HIGH8OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker...
CVE-2024-52056MEDIUM6.5Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any...
CVE-2024-52055MEDIUM4.9Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any f...
CVE-2024-52054LOW2.7Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an ...
CVE-2024-52053CRITICAL9.6Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated att...
CVE-2024-52052HIGH7.2Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom ap...
CVE-2024-52616MEDIUM5.3A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementi...
CVE-2024-52615MEDIUM5.3A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies at...
CVE-2024-51367CRITICAL9.8An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attacke...
CVE-2024-51366CRITICAL9.8An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbi...
CVE-2024-51365Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2024-51364HIGH8.8An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a...
CVE-2024-49588MEDIUM6.8Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now