2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38433MEDIUM6.7Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7...
CVE-2024-6256MEDIUM5.4The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-6138MEDIUM4.8The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some o...
CVE-2024-6026MEDIUM5.4The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could ...
CVE-2024-6025MEDIUM5.4The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, ...
CVE-2024-5444MEDIUM5.4The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputt...
CVE-2024-4655MEDIUM5.4The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputt...
CVE-2024-6554MEDIUM5.3The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclos...
CVE-2024-0619MEDIUM5.3The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2024-6210MEDIUM5.3The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. T...
CVE-2024-23485MEDIUM4.6Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the C...
CVE-2024-23317MEDIUM6.3External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local ...
CVE-2024-22387MEDIUM6.8External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface al...
CVE-2024-6650MEDIUM4.8A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problema...
CVE-2024-39561MEDIUM6.9An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Jun...
CVE-2024-39513MEDIUM6.8An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved al...
CVE-2024-39511MEDIUM6.8An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allo...
CVE-2024-6150MEDIUM4.3A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning
CVE-2024-6149MEDIUM6.1Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
CVE-2024-38354MEDIUM6.1CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rend...
CVE-2024-38353MEDIUM5.3CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and ...
CVE-2024-25076MEDIUM6.8An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The bootrom function respon...
CVE-2024-6649MEDIUM6.5A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as pro...
CVE-2024-5913MEDIUM6.8An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to...
CVE-2024-5912MEDIUM6.8An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now