2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3665MEDIUM5.4The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's H...
CVE-2024-3185MEDIUM6.8 A key used in logging.json does not follow the least privilege principle by default and is exposed to local users in th...
CVE-2024-0900MEDIUM4.3The Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding...
CVE-2024-3664MEDIUM4.3The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2024-4031MEDIUM4.4Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code.
CVE-2024-3889MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-2799MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image...
CVE-2024-2798MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-31857MEDIUM5.4Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote a...
CVE-2024-28890MEDIUM5.3Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerabil...
CVE-2024-2760MEDIUM5.5Bkav Home v7816, build 2403161130 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x222240 IO...
CVE-2024-1241MEDIUM5.5Watchdog Antivirus v1.6.415 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002014 IOCTL code o...
CVE-2024-32657MEDIUM5.4Hydra is a Continuous Integration service for Nix based projects. Attackers can execute arbitrary code in the browser co...
CVE-2024-32653MEDIUM6.1jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This ...
CVE-2024-32479MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper s...
CVE-2024-31036MEDIUM6.8A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of ...
CVE-2024-29368MEDIUM6.5An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extensio...
CVE-2024-29376MEDIUM6.4Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.
CVE-2024-28436MEDIUM6.1Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DA...
CVE-2024-3645MEDIUM6.4The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2024-27347MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: ...
CVE-2024-4026MEDIUM4.6Cross-Site Scripting (XSS) vulnerability in the Holded application. This vulnerability could allow an attacker to store ...
CVE-2024-28717MEDIUM4.9An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.
CVE-2024-22856MEDIUM5.4A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows auth...
CVE-2024-22815MEDIUM5.3An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cau...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now