2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-20861MEDIUM6.7Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause me...
CVE-2024-20859MEDIUM5.5Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pi...
CVE-2024-20858MEDIUM5.5Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 ...
CVE-2024-20857MEDIUM5.5Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows loc...
CVE-2024-20856MEDIUM4.3Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to acce...
CVE-2024-20821MEDIUM4.4A vulnerability possible to reconfigure OTP allows local attackers to transit RMA(Return Merchandise Authorization) mode...
CVE-2024-2913MEDIUM6.5A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite ...
CVE-2024-34413MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SliceWP allows Sto...
CVE-2024-1695MEDIUM5.7A potential security vulnerability has been identified in the HP Application Enabling Software Driver for certain HP PC ...
CVE-2024-4568MEDIUM5.5In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.
CVE-2024-33908MEDIUM5.3Missing Authorization vulnerability in Themesgrove WidgetKit.This issue affects WidgetKit: from n/a through 2.5.0.
CVE-2024-33907MEDIUM5.3Missing Authorization vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from...
CVE-2024-33600MEDIUM5.9nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-f...
CVE-2024-33576MEDIUM6.5Missing Authorization vulnerability in Ollybach WPPizza.This issue affects WPPizza: from n/a through 3.18.10.
CVE-2024-33121MEDIUM6.3Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.
CVE-2024-33117MEDIUM5.3crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.z...
CVE-2024-34390MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonMaster Post G...
CVE-2024-34389MEDIUM4.3Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6....
CVE-2024-34387MEDIUM4.3Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6....
CVE-2024-34381MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allow...
CVE-2024-34380MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conve...
CVE-2024-34379MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Restaurant and Cafe.This issue affects Restaurant and Cafe...
CVE-2024-34377MEDIUM4.3Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue...
CVE-2024-34376MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Edge...
CVE-2024-34375MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To W...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now