2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3600MEDIUM6.1The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a m...
CVE-2024-3598MEDIUM5.4The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button w...
CVE-2024-3560MEDIUM5.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id valu...
CVE-2024-27978MEDIUM6.5A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an auth...
CVE-2024-24991MEDIUM6.5A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an auth...
CVE-2024-23533MEDIUM6.5An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi...
CVE-2024-21846MEDIUM6.9An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET requ...
CVE-2024-32473MEDIUM6.5Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distribut...
CVE-2024-30927MEDIUM6.3Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-r...
CVE-2024-30926MEDIUM4.6Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/k...
CVE-2024-30925MEDIUM6.5Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-t...
CVE-2024-30924MEDIUM4.6Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin...
CVE-2024-30921MEDIUM5.4Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the...
CVE-2024-30107MEDIUM6.5HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized use...
CVE-2024-32474MEDIUM6.5Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to ...
CVE-2024-29987MEDIUM6.5Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-29986MEDIUM5.4Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
CVE-2024-23557MEDIUM4.3HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the u...
CVE-2024-32335MEDIUM5.4TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under ...
CVE-2024-32334MEDIUM6.5TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering und...
CVE-2024-32333MEDIUM4.3TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under t...
CVE-2024-32332MEDIUM6.1TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under th...
CVE-2024-32327MEDIUM5.5TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under...
CVE-2024-32326MEDIUM6.8TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in t...
CVE-2024-32470MEDIUM6.5Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission ch...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now