2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54919 | MEDIUM | 5.4 | 0.3% | Dec 9, 2024 | A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. Th... |
| CVE-2024-49603 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Dell PowerScale OneFS Versions 8.2.2.x through 9.9.0.x contain an incorrect specified argument vulnerability. A remote l... |
| CVE-2024-49602 | MEDIUM | 6.5 | 0.4% | Dec 9, 2024 | Dell PowerScale OneFS Versions 8.2.2.x through 9.8.0.x contain an improper resource unlocking vulnerability. A remote lo... |
| CVE-2024-42426 | MEDIUM | 6.5 | 0.4% | Dec 9, 2024 | Dell PowerScale OneFS Versions 9.5.0.x through 9.8.0.x contain an uncontrolled resource consumption vulnerability. A low... |
| CVE-2024-38485 | MEDIUM | 4.3 | 0.3% | Dec 9, 2024 | Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker co... |
| CVE-2024-11991 | MEDIUM | 6.5 | 0.2% | Dec 9, 2024 | Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of wri... |
| CVE-2024-54937 | MEDIUM | 5.3 | 0.5% | Dec 9, 2024 | A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to acc... |
| CVE-2024-54936 | MEDIUM | 5.4 | 0.4% | Dec 9, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management Syst... |
| CVE-2024-54218 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Missing Authorization vulnerability in thehp AIO Contact aio-contact.This issue affects AIO Contact: from n/a through <=... |
| CVE-2024-53949 | MEDIUM | 6.5 | 0.6% | Dec 9, 2024 | Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allo... |
| CVE-2024-53948 | MEDIUM | 5.3 | 0.8% | Dec 9, 2024 | Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Sup... |
| CVE-2024-53814 | MEDIUM | 6.5 | 0.4% | Dec 9, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Adnan Analytify wp-analytify... |
| CVE-2024-52391 | MEDIUM | 5.3 | 0.3% | Dec 9, 2024 | Missing Authorization vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a b... |
| CVE-2024-52385 | MEDIUM | 4.3 | 0.4% | Dec 9, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-54260 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blazethemes News K... |
| CVE-2024-54255 | MEDIUM | 4.7 | 0.4% | Dec 9, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in aviplugins.com Login Widget With Shortcode login-si... |
| CVE-2024-54254 | MEDIUM | 6.3 | 0.4% | Dec 9, 2024 | Missing Authorization vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter.This issue affec... |
| CVE-2024-54253 | MEDIUM | 5.4 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elemento... |
| CVE-2024-54251 | MEDIUM | 6.5 | 0.5% | Dec 9, 2024 | Missing Authorization vulnerability in prodigycommerce Prodigy Commerce prodigy-commerce allows Exploiting Incorrectly C... |
| CVE-2024-54247 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ABCBiz ABCBiz Addo... |
| CVE-2024-54232 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RRDevs RRAddons fo... |
| CVE-2024-54230 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Masud Hasan Unlock... |
| CVE-2024-54228 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technolo... |
| CVE-2024-54227 | MEDIUM | 4.3 | 0.4% | Dec 9, 2024 | Missing Authorization vulnerability in Dotstore Minimum and Maximum Quantity for WooCommerce min-and-max-quantity-for-wo... |
| CVE-2024-54224 | MEDIUM | 5.4 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quomodosoft Elemen... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now