2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11694 | MEDIUM | 6.1 | 0.5% | Nov 26, 2024 | Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS thr... |
| CVE-2024-11692 | MEDIUM | 4.3 | 0.5% | Nov 26, 2024 | An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possib... |
| CVE-2024-47250 | MEDIUM | 5 | 0.7% | Nov 26, 2024 | Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to ou... |
| CVE-2024-47249 | MEDIUM | 5 | 0.6% | Nov 26, 2024 | Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from control... |
| CVE-2024-47248 | MEDIUM | 6.3 | 0.7% | Nov 26, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafte... |
| CVE-2024-38834 | MEDIUM | 4.8 | 0.3% | Nov 26, 2024 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cl... |
| CVE-2024-38833 | MEDIUM | 5.4 | 0.4% | Nov 26, 2024 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to em... |
| CVE-2024-38832 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to vi... |
| CVE-2024-8899 | MEDIUM | 4.3 | 0.4% | Nov 26, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2024-50377 | MEDIUM | 6.5 | 0.2% | Nov 26, 2024 | A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-... |
| CVE-2024-50376 | MEDIUM | 5.2 | 0.5% | Nov 26, 2024 | A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting... |
| CVE-2024-10579 | MEDIUM | 4.3 | 0.4% | Nov 26, 2024 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access ... |
| CVE-2024-10308 | MEDIUM | 5.4 | 0.3% | Nov 26, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdow... |
| CVE-2024-11032 | MEDIUM | 6.1 | 0.4% | Nov 26, 2024 | The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg with... |
| CVE-2024-9170 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_produ... |
| CVE-2024-11192 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2024-11119 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' sh... |
| CVE-2024-11091 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-8772 | MEDIUM | 4.3 | 0.4% | Nov 26, 2024 | 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable ... |
| CVE-2024-6831 | MEDIUM | 4.4 | 0.2% | Nov 26, 2024 | Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove vie... |
| CVE-2024-34162 | MEDIUM | 5.3 | 0.8% | Nov 26, 2024 | The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But co... |
| CVE-2024-33616 | MEDIUM | 5.3 | 0.9% | Nov 26, 2024 | Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrat... |
| CVE-2024-32151 | MEDIUM | 5.9 | 1.3% | Nov 26, 2024 | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ... |
| CVE-2024-29978 | MEDIUM | 5.9 | 1.3% | Nov 26, 2024 | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ... |
| CVE-2024-29146 | MEDIUM | 5.9 | 0.9% | Nov 26, 2024 | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now