2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9481MEDIUM5.5An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS ...
CVE-2024-8499MEDIUM6.1The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site ...
CVE-2024-47790HIGH8.7** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-...
CVE-2024-47789HIGH8.7** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentic...
CVE-2024-47657MEDIUM6.5This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An aut...
CVE-2024-47656CRITICAL9.8This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API...
CVE-2024-47655HIGH8.8This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than t...
CVE-2024-47654HIGH7.5This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP request...
CVE-2024-47653MEDIUM6.5This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requ...
CVE-2024-47652HIGH8.1This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the...
CVE-2024-6400HIGH7.5Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finr...
CVE-2024-47651MEDIUM6.5This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint...
CVE-2024-9271MEDIUM5.4The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, ...
CVE-2024-9071MEDIUM5.4The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-9435MEDIUM6.1The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via U...
CVE-2024-9306MEDIUM4.8The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers...
CVE-2024-6444MEDIUM6.5No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client....
CVE-2024-9242MEDIUM5.4The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'me...
CVE-2024-8804MEDIUM5.4The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functiona...
CVE-2024-6443MEDIUM6.5In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is e...
CVE-2024-6442MEDIUM6.5In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.
CVE-2024-47855MEDIUM5.3util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.
CVE-2024-47854MEDIUM6.1An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitra...
CVE-2024-9445MEDIUM5.4The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medi...
CVE-2024-9421MEDIUM5.4The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now