2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11132MEDIUM5.4The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and incl...
CVE-2024-57237MEDIUM6.3Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endp...
CVE-2024-57004MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malici...
CVE-2024-50656MEDIUM6.1itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi...
CVE-2024-12510MEDIUM6.7If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. T...
CVE-2024-57967MEDIUM4.2PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated ...
CVE-2024-57175MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 ...
CVE-2024-54840MEDIUM6.1PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address...
CVE-2024-53943MEDIUM6.1An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln...
CVE-2024-53942MEDIUM4.8An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln...
CVE-2024-36437MEDIUM6.5The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any insta...
CVE-2024-55456MEDIUM6.5lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell
CVE-2024-38417MEDIUM5.5Information disclosure while processing IO control commands.
CVE-2024-38416MEDIUM5.5Information disclosure during audio playback.
CVE-2024-38414MEDIUM5.5Information disclosure while processing information on firmware image during core initialization.
CVE-2024-57522MEDIUM6.4SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An at...
CVE-2024-6790MEDIUM6.1Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valha...
CVE-2024-13347MEDIUM6.8The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in att...
CVE-2024-57966MEDIUM5libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.
CVE-2024-20147MEDIUM5.3In Bluetooth FW, there is a possible reachable assertion due to improper exception handling. This could lead to remote d...
CVE-2024-20142MEDIUM6.6In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of ...
CVE-2024-20141MEDIUM6.6In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of ...
CVE-2024-0131MEDIUM4.4NVIDIA GPU kernel driver for Windows and Linux contains a vulnerability where a potential user-mode attacker could read ...
CVE-2024-13775MEDIUM5.4The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to ...
CVE-2024-13612MEDIUM5.4The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now