2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53702 | MEDIUM | 5.3 | 0.3% | Dec 5, 2024 | Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup ... |
| CVE-2024-45319 | MEDIUM | 6.3 | 0.2% | Dec 5, 2024 | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authentica... |
| CVE-2024-12227 | MEDIUM | 6.8 | 0.2% | Dec 5, 2024 | A vulnerability, which was classified as problematic, was found in MSI Dragon Center up to 2.0.146.0. This affects the f... |
| CVE-2024-6516 | MEDIUM | 6.1 | 1.1% | Dec 5, 2024 | Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a clien... |
| CVE-2024-54127 | MEDIUM | 4.3 | 0.1% | Dec 5, 2024 | This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without pro... |
| CVE-2024-48844 | MEDIUM | 6.5 | 0.9% | Dec 5, 2024 | Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products:... |
| CVE-2024-12094 | MEDIUM | 5.4 | 0.1% | Dec 5, 2024 | This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the devic... |
| CVE-2024-45841 | MEDIUM | 6.5 | 0.5% | Dec 5, 2024 | Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/E... |
| CVE-2024-11779 | MEDIUM | 6.4 | 0.3% | Dec 5, 2024 | The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocaro... |
| CVE-2024-11420 | MEDIUM | 5.4 | 0.2% | Dec 5, 2024 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter i... |
| CVE-2024-11341 | MEDIUM | 4.3 | 0.2% | Dec 5, 2024 | The Simple Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-11324 | MEDIUM | 6.1 | 0.3% | Dec 5, 2024 | The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad... |
| CVE-2024-10848 | MEDIUM | 6.4 | 0.2% | Dec 5, 2024 | The NewsMunch theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versi... |
| CVE-2024-10777 | MEDIUM | 4.3 | 0.3% | Dec 5, 2024 | The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ... |
| CVE-2024-10056 | MEDIUM | 6.4 | 0.3% | Dec 5, 2024 | The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's liv... |
| CVE-2024-10937 | MEDIUM | 5.3 | 0.3% | Dec 5, 2024 | The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i... |
| CVE-2024-42195 | MEDIUM | 6.8 | 0.3% | Dec 5, 2024 | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary H... |
| CVE-2024-10178 | MEDIUM | 5.4 | 0.3% | Dec 5, 2024 | The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-10881 | MEDIUM | 6.4 | 0.2% | Dec 5, 2024 | The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in... |
| CVE-2024-12183 | MEDIUM | 5.4 | 0.4% | Dec 4, 2024 | A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS ... |
| CVE-2024-12182 | MEDIUM | 5.4 | 0.4% | Dec 4, 2024 | A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some ... |
| CVE-2024-12181 | MEDIUM | 5.4 | 0.4% | Dec 4, 2024 | A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown fun... |
| CVE-2024-12180 | MEDIUM | 5.4 | 0.4% | Dec 4, 2024 | A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file... |
| CVE-2024-54675 | MEDIUM | 6.1 | 0.2% | Dec 4, 2024 | app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ... |
| CVE-2024-54674 | MEDIUM | 6.1 | 0.2% | Dec 4, 2024 | app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom cluste... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now