2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-5096MEDIUM6.9A vulnerability classified as problematic was found in Hipcam Device up to 20240511. This vulnerability affects unknown ...
CVE-2024-36050MEDIUM4.3Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current sourc...
CVE-2024-28063MEDIUM6.1Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.
CVE-2024-36043MEDIUM6.1question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property.
CVE-2024-34083MEDIUM5.4aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on...
CVE-2024-5088MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter...
CVE-2024-4432MEDIUM6.4The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg...
CVE-2024-4709MEDIUM6.4The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner...
CVE-2024-4698MEDIUM6.4The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_l...
CVE-2024-2772MEDIUM5.4The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner...
CVE-2024-4849MEDIUM6.4The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘autoplay’ para...
CVE-2024-3811MEDIUM6.4The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'icon' shortco...
CVE-2024-4891MEDIUM5.4The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2024-4374MEDIUM5.4The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets ...
CVE-2024-3714MEDIUM5.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-4865MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter...
CVE-2024-23583MEDIUM6.7An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client D...
CVE-2024-35312MEDIUM6.2In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.
CVE-2024-25742MEDIUM6.5In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and c...
CVE-2024-34959MEDIUM5.5DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.
CVE-2024-5022MEDIUM4.4The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This...
CVE-2024-35190MEDIUM5.3Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP...
CVE-2024-5072MEDIUM6.5Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authentic...
CVE-2024-34241MEDIUM4.8A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript pa...
CVE-2024-31974MEDIUM6.3The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now