2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13115MEDIUM6.1The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places,...
CVE-2024-13114MEDIUM6.1The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter...
CVE-2024-44449MEDIUM6.1Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive informat...
CVE-2024-57498MEDIUM4.8Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the...
CVE-2024-57097MEDIUM4.8ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.
CVE-2024-56946MEDIUM5.3Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the s...
CVE-2024-11134MEDIUM6.5The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '...
CVE-2024-11133MEDIUM5.3The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '...
CVE-2024-11132MEDIUM5.4The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and incl...
CVE-2024-57237MEDIUM6.3Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endp...
CVE-2024-57004MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malici...
CVE-2024-50656MEDIUM6.1itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi...
CVE-2024-12510MEDIUM6.7If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. T...
CVE-2024-57967MEDIUM4.2PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated ...
CVE-2024-57175MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 ...
CVE-2024-54840MEDIUM6.1PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address...
CVE-2024-53943MEDIUM6.1An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln...
CVE-2024-53942MEDIUM4.8An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln...
CVE-2024-36437MEDIUM6.5The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any insta...
CVE-2024-55456MEDIUM6.5lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell
CVE-2024-38417MEDIUM5.5Information disclosure while processing IO control commands.
CVE-2024-38416MEDIUM5.5Information disclosure during audio playback.
CVE-2024-38414MEDIUM5.5Information disclosure while processing information on firmware image during core initialization.
CVE-2024-57522MEDIUM6.4SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An at...
CVE-2024-6790MEDIUM6.1Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valha...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now