2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11973 | MEDIUM | 6.1 | 0.3% | Dec 10, 2024 | The Quran multilanguage Text & Audio plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'soura... |
| CVE-2024-11945 | MEDIUM | 6.4 | 0.3% | Dec 10, 2024 | The Email Reminders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all vers... |
| CVE-2024-8256 | MEDIUM | 5.9 | 0.2% | Dec 10, 2024 | In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.... |
| CVE-2024-45709 | MEDIUM | 5.5 | 0.5% | Dec 10, 2024 | SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software b... |
| CVE-2024-11940 | MEDIUM | 6.4 | 0.3% | Dec 10, 2024 | The Property Hive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘price’ ... |
| CVE-2024-11107 | MEDIUM | 6.1 | 0.3% | Dec 10, 2024 | The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in... |
| CVE-2024-10708 | MEDIUM | 4.9 | 2.0% | Dec 10, 2024 | The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high ... |
| CVE-2024-11205 | MEDIUM | 6.5 | 0.7% | Dec 10, 2024 | The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2024-37144 | MEDIUM | 6.7 | 0.2% | Dec 10, 2024 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.... |
| CVE-2024-47585 | MEDIUM | 4.3 | 0.3% | Dec 10, 2024 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access level... |
| CVE-2024-47582 | MEDIUM | 5.3 | 0.4% | Dec 10, 2024 | Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which lead... |
| CVE-2024-47581 | MEDIUM | 4.3 | 0.2% | Dec 10, 2024 | SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated us... |
| CVE-2024-47580 | MEDIUM | 6.8 | 0.5% | Dec 10, 2024 | An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment.... |
| CVE-2024-47579 | MEDIUM | 6.8 | 0.5% | Dec 10, 2024 | An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file... |
| CVE-2024-32732 | MEDIUM | 5.3 | 0.3% | Dec 10, 2024 | Under certain conditions SAP BusinessObjects Business Intelligence platform allows an attacker to access information whi... |
| CVE-2024-9672 | MEDIUM | 5.4 | 0.2% | Dec 10, 2024 | A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute special... |
| CVE-2024-55635 | MEDIUM | 6.1 | 0.3% | Dec 10, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core... |
| CVE-2024-12393 | MEDIUM | 5.4 | 0.3% | Dec 10, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core... |
| CVE-2024-55601 | MEDIUM | 5.3 | 0.6% | Dec 9, 2024 | Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markd... |
| CVE-2024-12369 | MEDIUM | 4.2 | 0.2% | Dec 9, 2024 | A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc... |
| CVE-2024-54147 | MEDIUM | 6.8 | 0.2% | Dec 9, 2024 | Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not valid... |
| CVE-2024-53847 | MEDIUM | 5.1 | 0.4% | Dec 9, 2024 | The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS... |
| CVE-2024-52599 | MEDIUM | 5.4 | 0.3% | Dec 9, 2024 | Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edi... |
| CVE-2024-54935 | MEDIUM | 5.4 | 0.4% | Dec 9, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learn... |
| CVE-2024-11268 | MEDIUM | 5.5 | 0.2% | Dec 9, 2024 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now