2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-23190MEDIUM5.4Upsell shop information of an account can be manipulated to execute script code in the context of the users browser sess...
CVE-2024-23189MEDIUM5.4Embedded content references at tasks could be used to temporarily execute script code in the context of the users browse...
CVE-2024-1958MEDIUM4.8The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-1956MEDIUM6.1The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in t...
CVE-2024-1752MEDIUM6.1The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-1589MEDIUM6.1The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which co...
CVE-2024-1588MEDIUM6.8The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which co...
CVE-2024-1292MEDIUM4.7The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back i...
CVE-2024-23658MEDIUM4.4In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service wi...
CVE-2024-3434MEDIUM5.4A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability ...
CVE-2024-3433MEDIUM5.4A vulnerability classified as problematic has been found in PuneethReddyHC Event Management 1.0. Affected is an unknown ...
CVE-2024-31951MEDIUM6.5In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash i...
CVE-2024-31950MEDIUM6.5In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets...
CVE-2024-31949MEDIUM6.5In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability bec...
CVE-2024-31948MEDIUM6.5In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the ...
CVE-2024-3428MEDIUM6.1A vulnerability has been found in SourceCodester Online Courseware 1.0 and classified as problematic. This vulnerability...
CVE-2024-31349MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch MailMunc...
CVE-2024-31348MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testim...
CVE-2024-31346MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blocksmarket Gradi...
CVE-2024-31344MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative S...
CVE-2024-31306MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essent...
CVE-2024-31296MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects Boo...
CVE-2024-31258MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Micro.Company Form...
CVE-2024-31257MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Formsite Formsite ...
CVE-2024-31236MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Royal Royal Ele...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now