2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-34570MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elemento...
CVE-2024-34569MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katie Zotpress zot...
CVE-2024-34568MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeqx LetterPres...
CVE-2024-34566MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk...
CVE-2024-34565MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debug Info allows ...
CVE-2024-34564MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt Inc. Cou...
CVE-2024-34563MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoldAddons Gold Ad...
CVE-2024-34562MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Ad...
CVE-2024-4281MEDIUM5.4The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' short...
CVE-2024-4135MEDIUM5.4The WP Latest Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inclu...
CVE-2024-34572MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePrix Fancy El...
CVE-2024-34571MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill Himalay...
CVE-2024-34574MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpsoul Table Maker...
CVE-2024-34573MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pootlepress Pootle...
CVE-2024-3494MEDIUM6.4The Mesmerize Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mesmerize_co...
CVE-2024-1076MEDIUM6.5The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it...
CVE-2024-32674MEDIUM5.4Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is e...
CVE-2024-22266MEDIUM6.5 VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system ...
CVE-2024-4418MEDIUM6.2A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClien...
CVE-2024-4162MEDIUM4.4A buffer error in Panasonic KW Watcher versions 1.00 through 2.83 may allow attackers malicious read access to memory.
CVE-2024-1930MEDIUM6.5No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious...
CVE-2024-4456MEDIUM5.4In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payloa...
CVE-2024-23551MEDIUM6.5Database scanning using username and password stores the credentials in plaintext or encoded format within files at the ...
CVE-2024-23712MEDIUM5.5In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_acce...
CVE-2024-23709MEDIUM6.5In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now