2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11451 | MEDIUM | 6.4 | 0.3% | Dec 7, 2024 | The Zooom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zooom' shortcode in all ve... |
| CVE-2024-11436 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plu... |
| CVE-2024-11353 | MEDIUM | 4.3 | 0.3% | Dec 7, 2024 | The SMS for Lead Capture Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
| CVE-2024-11329 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The Comfino Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q... |
| CVE-2024-10046 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du... |
| CVE-2024-54138 | MEDIUM | 6.1 | 0.4% | Dec 6, 2024 | NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to it... |
| CVE-2024-7875 | MEDIUM | 5.3 | 0.5% | Dec 6, 2024 | Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks... |
| CVE-2024-7874 | MEDIUM | 5.3 | 0.5% | Dec 6, 2024 | Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks... |
| CVE-2024-12326 | MEDIUM | 6.1 | 0.2% | Dec 6, 2024 | Jirafeau normally prevents browser preview for SVG files due to the possibility that manipulated SVG files could be expl... |
| CVE-2024-0139 | MEDIUM | 4.4 | 0.1% | Dec 6, 2024 | NVIDIA Base Command Manager and Bright Cluster Manager for Linux contain an insecure temporary file vulnerability. A suc... |
| CVE-2024-47791 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possibl... |
| CVE-2024-47146 | MEDIUM | 6.5 | 0.3% | Dec 6, 2024 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial nu... |
| CVE-2024-52558 | MEDIUM | 6.9 | 0.6% | Dec 6, 2024 | The affected product is vulnerable to an integer underflow. An unauthenticated attacker could send a malformed HTTP requ... |
| CVE-2024-48703 | MEDIUM | 4.8 | 0.3% | Dec 6, 2024 | PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.... |
| CVE-2024-47043 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial n... |
| CVE-2024-55268 | MEDIUM | 6.1 | 0.4% | Dec 6, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /covidtms/registered-user-testing.php in PHPGurukul CO... |
| CVE-2024-48866 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating sys... |
| CVE-2024-50677 | MEDIUM | 6.1 | 0.5% | Dec 6, 2024 | A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or ... |
| CVE-2024-30129 | MEDIUM | 5.3 | 0.3% | Dec 6, 2024 | The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the ... |
| CVE-2024-42196 | MEDIUM | 5.5 | 0.1% | Dec 6, 2024 | HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP ... |
| CVE-2024-54213 | MEDIUM | 6.5 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zionbuilder ZionBu... |
| CVE-2024-54212 | MEDIUM | 5.4 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical ... |
| CVE-2024-54211 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderl... |
| CVE-2024-54210 | MEDIUM | 6.5 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codexshaper Advanc... |
| CVE-2024-54207 | MEDIUM | 5.9 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Marka WordPress... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now