2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-32051MEDIUM6.5Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is ...
CVE-2024-3261MEDIUM4.8The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields befor...
CVE-2024-2404MEDIUM5.4The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow l...
CVE-2024-2402MEDIUM5.4The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-1756MEDIUM6.5The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, a...
CVE-2024-1743MEDIUM5.9The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before ou...
CVE-2024-4075MEDIUM6.1A vulnerability classified as problematic has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. T...
CVE-2024-4074MEDIUM6.1A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been rated as problematic...
CVE-2024-4073MEDIUM5.4A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been declared as problema...
CVE-2024-4072MEDIUM5.4A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been classified as proble...
CVE-2024-30886MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execut...
CVE-2024-32875MEDIUM6.1Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown f...
CVE-2024-32869MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.2.7, when using...
CVE-2024-31208MEDIUM6.5Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse ins...
CVE-2024-21979MEDIUM5.3 An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with a...
CVE-2024-21972MEDIUM5.3 An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with a...
CVE-2024-33213MEDIUM6.5Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterfac...
CVE-2024-32679MEDIUM5.3Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a...
CVE-2024-31804MEDIUM6.7An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privile...
CVE-2024-2477MEDIUM5.4The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an up...
CVE-2024-3911MEDIUM6.5An unauthenticated remote attacker can deceive users into performing unintended actions due to improper restriction of r...
CVE-2024-30800MEDIUM5.6PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the ...
CVE-2024-26922MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping o...
CVE-2024-3491MEDIUM6.4The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-3732MEDIUM5.4The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to St...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now