2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53281 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functi... |
| CVE-2024-53280 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center pol... |
| CVE-2024-53279 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station funct... |
| CVE-2024-55582 | MEDIUM | 5.7 | 0.1% | Dec 9, 2024 | Oxide before 6 has unencrypted Control Plane datastores. |
| CVE-2024-55578 | MEDIUM | 4.3 | 0.3% | Dec 9, 2024 | Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log f... |
| CVE-2024-55566 | MEDIUM | 6.6 | 0.2% | Dec 9, 2024 | ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded... |
| CVE-2024-55565 | MEDIUM | 4.3 | 0.7% | Dec 9, 2024 | nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version. |
| CVE-2024-55563 | MEDIUM | 5.3 | 0.6% | Dec 9, 2024 | Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024... |
| CVE-2024-12348 | MEDIUM | 6.1 | 0.4% | Dec 9, 2024 | A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is ... |
| CVE-2024-12347 | MEDIUM | 6.9 | 0.6% | Dec 9, 2024 | A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This ... |
| CVE-2024-12346 | MEDIUM | 5.3 | 0.4% | Dec 9, 2024 | A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unk... |
| CVE-2024-47107 | MEDIUM | 5.4 | 0.2% | Dec 7, 2024 | IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed... |
| CVE-2024-41762 | MEDIUM | 6.5 | 0.4% | Dec 7, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv... |
| CVE-2024-37071 | MEDIUM | 6.5 | 0.4% | Dec 7, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user... |
| CVE-2024-11464 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in ... |
| CVE-2024-11457 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Sc... |
| CVE-2024-11380 | MEDIUM | 6.4 | 0.2% | Dec 7, 2024 | The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortco... |
| CVE-2024-12253 | MEDIUM | 5.4 | 0.3% | Dec 7, 2024 | The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2024-12128 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected ... |
| CVE-2024-11374 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The TWChat – Send or receive messages from users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du... |
| CVE-2024-11367 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The Smoove connector for Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the... |
| CVE-2024-11183 | MEDIUM | 4.8 | 0.3% | Dec 7, 2024 | The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-8679 | MEDIUM | 6.8 | 0.4% | Dec 7, 2024 | The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via t... |
| CVE-2024-7894 | MEDIUM | 5.3 | 0.3% | Dec 7, 2024 | The If Menu plugin for WordPress is vulnerable to unauthorized modification of the plugin's license key due to a missing... |
| CVE-2024-12257 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The CardGate Payments for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now