2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-57721MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.
CVE-2024-57720MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.
CVE-2024-57719MEDIUM6.5lunasvg v3.0.0 was discovered to contain a segmentation violation via the component blend_transformed_tiled_argb.isra.0.
CVE-2024-12477MEDIUM5.4The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all v...
CVE-2024-56923MEDIUM5.4Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silver...
CVE-2024-56914MEDIUM5.7D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.
CVE-2024-9310MEDIUM6By utilizing software-defined radios and a custom low-latency processing pipeline, RF signals with spoofed location data...
CVE-2024-51457MEDIUM5.4IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-...
CVE-2024-55488MEDIUM6.5A stored cross-site scripting (XSS) vulnerability in Umbraco CMS v14.3.1 allows attackers to execute arbitrary web scrip...
CVE-2024-42013MEDIUM6.4In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attac...
CVE-2024-42012MEDIUM5.7GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is c...
CVE-2024-10929MEDIUM5.1In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may ...
CVE-2024-24432MEDIUM5.3A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service...
CVE-2024-13447MEDIUM4.3The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2024-13360MEDIUM5.4The AI Power: Complete AI Pack plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, ...
CVE-2024-13319MEDIUM6.1The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg...
CVE-2024-13406MEDIUM6.1The XML for Google Merchant Center plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'feed_id...
CVE-2024-12117MEDIUM5.4The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-12879MEDIUM4.3The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2024-13590MEDIUM5.4The Ketchup Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spacer' short...
CVE-2024-13584MEDIUM5.4The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-13426MEDIUM5.3The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2...
CVE-2024-49736MEDIUM5.5In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a lo...
CVE-2024-49733MEDIUM5.5In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to ...
CVE-2024-43763MEDIUM6.5In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This coul...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now