2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-35782MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Codeless Co...
CVE-2024-35668MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsl...
CVE-2024-35666MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themesflat ...
CVE-2024-35664MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpvividplugins WPv...
CVE-2024-35655MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brave Brave brave-...
CVE-2024-35654MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CyberChimps...
CVE-2024-35634MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wow-Company Woocommerce ...
CVE-2024-33568MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulner...
CVE-2024-36801MEDIUM5.9A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid par...
CVE-2024-33541MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BetterAddons Better Elem...
CVE-2024-5463MEDIUM6.5A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in t...
CVE-2024-4637MEDIUM5.4The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...
CVE-2024-4581MEDIUM5.4The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widge...
CVE-2024-5485MEDIUM6.4The SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! plugin for WordPress is vulnerable to St...
CVE-2024-20886MEDIUM6.2Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary d...
CVE-2024-20882MEDIUM4.6Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary d...
CVE-2024-20881MEDIUM6.7Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local privileged attackers...
CVE-2024-20880MEDIUM6.8Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to ove...
CVE-2024-20875MEDIUM5.5Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to ac...
CVE-2024-20873MEDIUM6Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attack...
CVE-2024-4997MEDIUM5.3The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links...
CVE-2024-4857MEDIUM6.1The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape some form submissions, which could al...
CVE-2024-4750MEDIUM5.3The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private...
CVE-2024-4697MEDIUM5.4The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’...
CVE-2024-4462MEDIUM4.4The Nafeza Prayer Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now