2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33626 | MEDIUM | 5.3 | 0.4% | Oct 30, 2024 | The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure ... |
| CVE-2024-33623 | HIGH | 7.5 | 11.4% | Oct 30, 2024 | A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially ... |
| CVE-2024-33603 | MEDIUM | 5.3 | 8.8% | Oct 30, 2024 | The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenti... |
| CVE-2024-32946 | MEDIUM | 5.9 | 0.3% | Oct 30, 2024 | A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitte... |
| CVE-2024-31152 | HIGH | 7.5 | 17.2% | Oct 30, 2024 | The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web applicat... |
| CVE-2024-31151 | CRITICAL | 9.8 | 0.7% | Oct 30, 2024 | A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthoriz... |
| CVE-2024-28875 | HIGH | 8.1 | 0.7% | Oct 30, 2024 | A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthoriz... |
| CVE-2024-28052 | HIGH | 7.5 | 0.7% | Oct 30, 2024 | The WBR-6012 is a wireless SOHO router. It is a low-cost device which functions as an internet gateway for homes and sma... |
| CVE-2024-24777 | HIGH | 8.8 | 7.0% | Oct 30, 2024 | A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R... |
| CVE-2024-23309 | HIGH | 8.1 | 0.9% | Oct 30, 2024 | The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due... |
| CVE-2024-51304 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-3935 | MEDIUM | 6.5 | 0.8% | Oct 30, 2024 | In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridg... |
| CVE-2024-10525 | CRITICAL | 9.8 | 57.9% | Oct 30, 2024 | In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no rea... |
| CVE-2024-9388 | MEDIUM | 5.4 | 0.3% | Oct 30, 2024 | The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i... |
| CVE-2024-8512 | CRITICAL | 9.1 | 1.0% | Oct 30, 2024 | The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 v... |
| CVE-2024-9632 | HIGH | 7.8 | 0.9% | Oct 30, 2024 | A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker ma... |
| CVE-2024-50512 | MEDIUM | 5.3 | 0.3% | Oct 30, 2024 | Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping posti-shipping allows... |
| CVE-2024-50511 | CRITICAL | 9.9 | 0.5% | Oct 30, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in donimedia WP donimedia carousel wp-donimedia-carousel a... |
| CVE-2024-50510 | CRITICAL | 10 | 1.0% | Oct 30, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allow... |
| CVE-2024-50509 | HIGH | 8.6 | 1.3% | Oct 30, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommer... |
| CVE-2024-50508 | HIGH | 7.5 | 1.0% | Oct 30, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommer... |
| CVE-2024-50507 | CRITICAL | 9.8 | 1.0% | Oct 30, 2024 | Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This i... |
| CVE-2024-50506 | HIGH | 8.8 | 0.4% | Oct 30, 2024 | Incorrect Privilege Assignment vulnerability in azexo Marketing Automation by AZEXO marketing-automation-by-azexo allows... |
| CVE-2024-50504 | HIGH | 8.8 | 0.5% | Oct 30, 2024 | Incorrect Privilege Assignment vulnerability in webxmedia Bulk Change Role bulk-role-change allows Privilege Escalation.... |
| CVE-2024-50503 | CRITICAL | 9.8 | 0.5% | Oct 30, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authen... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now