2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38271MEDIUM4.8There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporar...
CVE-2024-25637MEDIUM5.4October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not ...
CVE-2024-4604MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Ma...
CVE-2024-5215MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multip...
CVE-2024-5573MEDIUM5.9The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could...
CVE-2024-5473MEDIUM4The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-5332MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Ca...
CVE-2024-5199MEDIUM5.4The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes befor...
CVE-2024-5169MEDIUM4.8The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-5071MEDIUM6.5The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing at...
CVE-2024-4959MEDIUM4.8The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could all...
CVE-2024-4957MEDIUM4.3The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could all...
CVE-2024-4106MEDIUM5.3A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwor...
CVE-2024-4105MEDIUM5.8A vulnerability has been found in FAST/TOOLS and CI Server. The affected product's WEB HMI server's function to process ...
CVE-2024-3633MEDIUM5.4The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with...
CVE-2024-34580MEDIUM5.3Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification wit...
CVE-2024-21520MEDIUM6.1Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_lon...
CVE-2024-37139MEDIUM6.5Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a ...
CVE-2024-37138MEDIUM6.8Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path t...
CVE-2024-27867MEDIUM4.3An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A3...
CVE-2024-29175MEDIUM5.9Dell PowerProtect Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.40, LTS 7.10.1.30 contain an weak cryptographic alg...
CVE-2024-29174MEDIUM4.4Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A loca...
CVE-2024-29173MEDIUM4.9Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Server-Side Request For...
CVE-2024-28973MEDIUM4.8Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Stored Cross-Site Scrip...
CVE-2024-5173MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Vi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now