2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1905MEDIUM5.9The Smart Forms WordPress plugin before 2.6.96 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-33649MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpOpal Opal Widget...
CVE-2024-33648MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemory Grubb Recen...
CVE-2024-33643MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey Lampert Adv...
CVE-2024-33640MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LBell Pretty Googl...
CVE-2024-3096MEDIUM6.5In PHP  version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() ...
CVE-2024-2756MEDIUM6.5Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site at...
CVE-2024-4297MEDIUM4.9The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to fil...
CVE-2024-4296MEDIUM4.9The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filte...
CVE-2024-33903MEDIUM5.9In CARLA through 0.9.15.2, the collision sensor mishandles some situations involving pedestrians or bicycles, in part be...
CVE-2024-33883MEDIUM4The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
CVE-2024-4293MEDIUM5.4A vulnerability classified as problematic was found in PHPGurukul Doctor Appointment Management System 1.0. Affected by ...
CVE-2024-33851MEDIUM4.3phpecc, as used in paragonie/phpecc before 2.0.1, has a branch-based timing leak in Point addition. (This is related to ...
CVE-2024-4292MEDIUM6.5A vulnerability classified as critical has been found in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2. Affected ...
CVE-2024-4257MEDIUM6.5A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This...
CVE-2024-4256MEDIUM4.8A vulnerability was found in Techkshetra Info Solutions Savsoft Quiz 6.0 and classified as problematic. Affected by this...
CVE-2024-3309MEDIUM5.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget's...
CVE-2024-2838MEDIUM6.4The WPC Composite Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wo...
CVE-2024-2258MEDIUM5.4The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored ...
CVE-2024-31828MEDIUM6.1Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensit...
CVE-2024-31741MEDIUM6.1Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string i...
CVE-2024-32887MEDIUM5.5Sidekiq is simple, efficient background processing for Ruby. Sidekiq is reflected XSS vulnerability. The value of substr...
CVE-2024-28326MEDIUM6.8Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access ...
CVE-2024-28325MEDIUM6.1Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access ...
CVE-2024-4235MEDIUM4.9A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now