2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-22813MEDIUM4.4An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP addres...
CVE-2024-22809MEDIUM6.5Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code...
CVE-2024-22807MEDIUM6.5An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the fl...
CVE-2024-32691MEDIUM5.3Missing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Produ...
CVE-2024-32688MEDIUM6.5Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0.
CVE-2024-32687MEDIUM4.3Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Fr...
CVE-2024-32698MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy...
CVE-2024-32697MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HelloAsso allows S...
CVE-2024-32696MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Infog...
CVE-2024-32690MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood RSS ...
CVE-2024-30799MEDIUM4.4An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of serv...
CVE-2024-28722MEDIUM6.3Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbit...
CVE-2024-29217MEDIUM4.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This...
CVE-2024-4022MEDIUM5.3A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been rated a...
CVE-2024-4021MEDIUM5.3A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been declare...
CVE-2024-4019MEDIUM6.3A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up to 20240411. Affected i...
CVE-2024-4014MEDIUM6.4The hCaptcha for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf7-hcaptc...
CVE-2024-1730MEDIUM5.4The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slid...
CVE-2024-1057MEDIUM5.4The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2024-31994MEDIUM6.5Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an a...
CVE-2024-32392MEDIUM4.5Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functio...
CVE-2024-31993MEDIUM4.5Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the scrape_image function will retrieve an imag...
CVE-2024-31992MEDIUM6.5Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c...
CVE-2024-31584MEDIUM5.5Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader....
CVE-2024-1681MEDIUM5.3corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake lo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now