2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54004 | MEDIUM | 4.3 | 0.8% | Nov 27, 2024 | Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects ... |
| CVE-2024-51228 | MEDIUM | 6.8 | 3.8% | Nov 27, 2024 | An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300R... |
| CVE-2024-37816 | MEDIUM | 4.2 | 0.2% | Nov 27, 2024 | Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow. |
| CVE-2024-21703 | MEDIUM | 6.4 | 0.2% | Nov 27, 2024 | This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center a... |
| CVE-2024-11860 | MEDIUM | 6.5 | 0.8% | Nov 27, 2024 | A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af... |
| CVE-2024-46055 | MEDIUM | 4.8 | 0.4% | Nov 27, 2024 | OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names. |
| CVE-2024-11862 | MEDIUM | 5.1 | 0.1% | Nov 27, 2024 | Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render hal... |
| CVE-2024-53635 | MEDIUM | 4.8 | 0.5% | Nov 27, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COV... |
| CVE-2024-42328 | MEDIUM | 5.5 | 0.2% | Nov 27, 2024 | When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allo... |
| CVE-2024-42326 | MEDIUM | 4.4 | 0.2% | Nov 27, 2024 | There was discovered a use after free bug in browser.c in the es_browser_get_variant function |
| CVE-2024-11009 | MEDIUM | 4.9 | 0.4% | Nov 27, 2024 | The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable... |
| CVE-2024-11025 | MEDIUM | 5.4 | 0.2% | Nov 27, 2024 | An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administrat... |
| CVE-2024-10521 | MEDIUM | 4.3 | 0.2% | Nov 27, 2024 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ... |
| CVE-2024-10895 | MEDIUM | 6.4 | 0.2% | Nov 27, 2024 | The Counter Up – Animated Number Counter & Milestone Showcase plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-10580 | MEDIUM | 5.3 | 0.4% | Nov 27, 2024 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form su... |
| CVE-2024-10175 | MEDIUM | 6.4 | 0.3% | Nov 27, 2024 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2024-11083 | MEDIUM | 5.3 | 0.4% | Nov 27, 2024 | The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2024-11820 | MEDIUM | 5.4 | 0.4% | Nov 27, 2024 | A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This is... |
| CVE-2024-53849 | MEDIUM | 4.8 | 0.2% | Nov 27, 2024 | editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing).... |
| CVE-2024-43784 | MEDIUM | 5.7 | 0.3% | Nov 26, 2024 | lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have ... |
| CVE-2024-11743 | MEDIUM | 4.3 | 0.3% | Nov 26, 2024 | A vulnerability, which was classified as problematic, was found in SourceCodester Best House Rental Management System 1.... |
| CVE-2024-11742 | MEDIUM | 5.4 | 0.5% | Nov 26, 2024 | A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management Syst... |
| CVE-2024-10240 | MEDIUM | 5.3 | 0.5% | Nov 26, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting... |
| CVE-2024-53844 | MEDIUM | 6.3 | 0.4% | Nov 26, 2024 | E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerab... |
| CVE-2024-53620 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execut... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now