2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-5739MEDIUM6.1The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vuln...
CVE-2024-28970MEDIUM4.4Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileg...
CVE-2024-0160MEDIUM6.8Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system c...
CVE-2024-5892MEDIUM6.4The Divi Torque Lite – Divi Theme and Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-4924MEDIUM6.1The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could...
CVE-2024-36454MEDIUM5.3Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 S...
CVE-2024-0427MEDIUM6.3The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.4.1 does not properly escape user-controll...
CVE-2024-3559MEDIUM5.4The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]'...
CVE-2024-5553MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several...
CVE-2024-4564MEDIUM6.4The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress...
CVE-2024-4892MEDIUM5.4The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in ver...
CVE-2024-36103MEDIUM6.8OS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a...
CVE-2024-35225MEDIUM6.1Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authen...
CVE-2024-5843MEDIUM6.5Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate...
CVE-2024-5840MEDIUM6.5Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access c...
CVE-2024-5839MEDIUM6.5Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to po...
CVE-2024-5646MEDIUM5.4The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute with...
CVE-2024-4669MEDIUM5.4The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Basic Slider, U...
CVE-2024-34406MEDIUM5.3Improper exception handling in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to cause ...
CVE-2024-28024MEDIUM4.1A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource th...
CVE-2024-28022MEDIUM6.5A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary...
CVE-2024-5851MEDIUM5.3A vulnerability classified as problematic has been found in playSMS up to 1.4.7. Affected is an unknown function of the ...
CVE-2024-36821MEDIUM6.8Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest ...
CVE-2024-35263MEDIUM5.7Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-35255MEDIUM5.5Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now