2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11379 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all v... |
| CVE-2024-9769 | MEDIUM | 4.8 | 0.3% | Dec 6, 2024 | The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-10836 | MEDIUM | 6.1 | 0.4% | Dec 6, 2024 | The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions u... |
| CVE-2024-10247 | MEDIUM | 4.9 | 0.5% | Dec 6, 2024 | The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection... |
| CVE-2024-49041 | MEDIUM | 4.3 | 1.1% | Dec 6, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-11149 | MEDIUM | 5.5 | 0.1% | Dec 6, 2024 | In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs. |
| CVE-2024-53457 | MEDIUM | 5.4 | 42.5% | Dec 5, 2024 | A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows ... |
| CVE-2024-10933 | MEDIUM | 5.5 | 0.3% | Dec 5, 2024 | In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid ... |
| CVE-2024-54128 | MEDIUM | 4.6 | 0.3% | Dec 5, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a f... |
| CVE-2024-53846 | MEDIUM | 5.5 | 0.2% | Dec 5, 2024 | OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainl... |
| CVE-2024-54001 | MEDIUM | 5.5 | 0.4% | Dec 5, 2024 | Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the... |
| CVE-2024-53471 | MEDIUM | 6.1 | 0.3% | Dec 5, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3... |
| CVE-2024-53470 | MEDIUM | 6.1 | 0.4% | Dec 5, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA... |
| CVE-2024-12247 | MEDIUM | 4.3 | 0.2% | Dec 5, 2024 | Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updat... |
| CVE-2024-12232 | MEDIUM | 6.1 | 0.4% | Dec 5, 2024 | A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulner... |
| CVE-2024-10716 | MEDIUM | 4.8 | 0.2% | Dec 5, 2024 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. |
| CVE-2024-11942 | MEDIUM | 5.9 | 0.4% | Dec 5, 2024 | A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10. |
| CVE-2024-54679 | MEDIUM | 6.5 | 0.9% | Dec 5, 2024 | CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions. |
| CVE-2024-53702 | MEDIUM | 5.3 | 0.3% | Dec 5, 2024 | Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup ... |
| CVE-2024-45319 | MEDIUM | 6.3 | 0.2% | Dec 5, 2024 | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authentica... |
| CVE-2024-12227 | MEDIUM | 6.8 | 0.2% | Dec 5, 2024 | A vulnerability, which was classified as problematic, was found in MSI Dragon Center up to 2.0.146.0. This affects the f... |
| CVE-2024-6516 | MEDIUM | 6.1 | 1.1% | Dec 5, 2024 | Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a clien... |
| CVE-2024-54127 | MEDIUM | 4.3 | 0.1% | Dec 5, 2024 | This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without pro... |
| CVE-2024-48844 | MEDIUM | 6.5 | 0.9% | Dec 5, 2024 | Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products:... |
| CVE-2024-12094 | MEDIUM | 5.4 | 0.1% | Dec 5, 2024 | This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the devic... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now