2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10493 | MEDIUM | 5.4 | 0.3% | Nov 28, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress pl... |
| CVE-2024-10473 | MEDIUM | 5.4 | 0.4% | Nov 28, 2024 | The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing the... |
| CVE-2024-53008 | MEDIUM | 5.3 | 1.0% | Nov 28, 2024 | Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulner... |
| CVE-2024-53858 | MEDIUM | 6.5 | 0.3% | Nov 27, 2024 | The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that c... |
| CVE-2024-53260 | MEDIUM | 6.8 | 0.5% | Nov 27, 2024 | Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first a... |
| CVE-2024-53855 | MEDIUM | 4.3 | 0.4% | Nov 27, 2024 | Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management wit... |
| CVE-2024-53264 | MEDIUM | 5.1 | 0.8% | Nov 27, 2024 | bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in ... |
| CVE-2024-54004 | MEDIUM | 4.3 | 0.8% | Nov 27, 2024 | Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects ... |
| CVE-2024-51228 | MEDIUM | 6.8 | 3.8% | Nov 27, 2024 | An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300R... |
| CVE-2024-37816 | MEDIUM | 4.2 | 0.2% | Nov 27, 2024 | Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow. |
| CVE-2024-21703 | MEDIUM | 6.4 | 0.2% | Nov 27, 2024 | This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center a... |
| CVE-2024-11860 | MEDIUM | 6.5 | 0.8% | Nov 27, 2024 | A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af... |
| CVE-2024-46055 | MEDIUM | 4.8 | 0.4% | Nov 27, 2024 | OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names. |
| CVE-2024-11862 | MEDIUM | 5.1 | 0.1% | Nov 27, 2024 | Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render hal... |
| CVE-2024-53635 | MEDIUM | 4.8 | 0.5% | Nov 27, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COV... |
| CVE-2024-42328 | MEDIUM | 5.5 | 0.2% | Nov 27, 2024 | When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allo... |
| CVE-2024-42326 | MEDIUM | 4.4 | 0.2% | Nov 27, 2024 | There was discovered a use after free bug in browser.c in the es_browser_get_variant function |
| CVE-2024-11009 | MEDIUM | 4.9 | 0.4% | Nov 27, 2024 | The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable... |
| CVE-2024-11025 | MEDIUM | 5.4 | 0.2% | Nov 27, 2024 | An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administrat... |
| CVE-2024-10521 | MEDIUM | 4.3 | 0.2% | Nov 27, 2024 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ... |
| CVE-2024-10895 | MEDIUM | 6.4 | 0.2% | Nov 27, 2024 | The Counter Up – Animated Number Counter & Milestone Showcase plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-10580 | MEDIUM | 5.3 | 0.4% | Nov 27, 2024 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form su... |
| CVE-2024-10175 | MEDIUM | 6.4 | 0.3% | Nov 27, 2024 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2024-11083 | MEDIUM | 5.3 | 0.4% | Nov 27, 2024 | The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2024-11820 | MEDIUM | 5.4 | 0.4% | Nov 27, 2024 | A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This is... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now