2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12204MEDIUM5.4The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne...
CVE-2024-11327MEDIUM6.1The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is...
CVE-2024-9133MEDIUM5.6A user with administrator privileges is able to retrieve authentication tokens
CVE-2024-7142MEDIUM4.6On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA...
CVE-2024-47517MEDIUM6.8Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
CVE-2024-7095MEDIUM4.3On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under s...
CVE-2024-5872MEDIUM6.5On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, whi...
CVE-2024-54998MEDIUM5.4MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter ...
CVE-2024-54997MEDIUM5.4MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field ...
CVE-2024-54994MEDIUM6.5MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_nam...
CVE-2024-6437MEDIUM5.8On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next ...
CVE-2024-33299MEDIUM4.7Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the Firs...
CVE-2024-33298MEDIUM6.1Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code v...
CVE-2024-33297MEDIUM4.7Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the camp...
CVE-2024-54910MEDIUM4.7Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.
CVE-2024-6880MEDIUM6.9During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping ...
CVE-2024-57222MEDIUM6.3Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...
CVE-2024-54687MEDIUM6.1Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndS...
CVE-2024-57214MEDIUM6.3TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parame...
CVE-2024-57213MEDIUM6.3TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd para...
CVE-2024-57212MEDIUM5.1TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode paramet...
CVE-2024-54849MEDIUM5.9An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitiv...
CVE-2024-54847MEDIUM5.9An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access ...
CVE-2024-54846MEDIUM5.9An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data o...
CVE-2024-50807MEDIUM6.1Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf e...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now