2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33626MEDIUM5.3The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure ...
CVE-2024-33623HIGH7.5A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially ...
CVE-2024-33603MEDIUM5.3The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenti...
CVE-2024-32946MEDIUM5.9A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitte...
CVE-2024-31152HIGH7.5The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web applicat...
CVE-2024-31151CRITICAL9.8A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthoriz...
CVE-2024-28875HIGH8.1A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthoriz...
CVE-2024-28052HIGH7.5The WBR-6012 is a wireless SOHO router. It is a low-cost device which functions as an internet gateway for homes and sma...
CVE-2024-24777HIGH8.8A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R...
CVE-2024-23309HIGH8.1The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due...
CVE-2024-51304HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-3935MEDIUM6.5In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridg...
CVE-2024-10525CRITICAL9.8In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no rea...
CVE-2024-9388MEDIUM5.4The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i...
CVE-2024-8512CRITICAL9.1The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 v...
CVE-2024-9632HIGH7.8A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker ma...
CVE-2024-50512MEDIUM5.3Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping posti-shipping allows...
CVE-2024-50511CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in donimedia WP donimedia carousel wp-donimedia-carousel a...
CVE-2024-50510CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allow...
CVE-2024-50509HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommer...
CVE-2024-50508HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommer...
CVE-2024-50507CRITICAL9.8Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This i...
CVE-2024-50506HIGH8.8Incorrect Privilege Assignment vulnerability in azexo Marketing Automation by AZEXO marketing-automation-by-azexo allows...
CVE-2024-50504HIGH8.8Incorrect Privilege Assignment vulnerability in webxmedia Bulk Change Role bulk-role-change allows Privilege Escalation....
CVE-2024-50503CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authen...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now