2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-23441MEDIUM5.5Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the ...
CVE-2024-1006MEDIUM5.3A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affec...
CVE-2024-22559MEDIUM5.4LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.
CVE-2024-23792MEDIUM6.5When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. Th...
CVE-2024-0212MEDIUM6.5The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attacke...
CVE-2024-23782MEDIUM5.4Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series v...
CVE-2024-0958MEDIUM5.4A vulnerability was found in CodeAstro Stock Management System 1.0 and classified as problematic. This issue affects som...
CVE-2024-0618MEDIUM4.8The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vuln...
CVE-2024-0824MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anythi...
CVE-2024-0697MEDIUM4.9The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versi...
CVE-2024-0667MEDIUM6.3The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-S...
CVE-2024-0664MEDIUM4.8The Meks Smart Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meks Smart Social...
CVE-2024-23506MEDIUM6.5Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue af...
CVE-2024-0948MEDIUM6.1** DISPUTED ** A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This issue af...
CVE-2024-0944MEDIUM5.3A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue ...
CVE-2024-0943MEDIUM5.3A vulnerability was found in Totolink N350RT 9.3.5u.6255. It has been declared as problematic. Affected by this vulnerab...
CVE-2024-0942MEDIUM4.3A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected i...
CVE-2024-20305MEDIUM4.8A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att...
CVE-2024-23820MEDIUM6.5OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In ...
CVE-2024-22551MEDIUM6.1WhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/...
CVE-2024-22550MEDIUM6.1An arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to exe...
CVE-2024-23896MEDIUM6.1A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n...
CVE-2024-23894MEDIUM6.1A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n...
CVE-2024-23893MEDIUM6.1A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n...
CVE-2024-23892MEDIUM6.1A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now