2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38832 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to vi... |
| CVE-2024-8899 | MEDIUM | 4.3 | 0.4% | Nov 26, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2024-50377 | MEDIUM | 6.5 | 0.2% | Nov 26, 2024 | A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-... |
| CVE-2024-50376 | MEDIUM | 5.2 | 0.5% | Nov 26, 2024 | A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting... |
| CVE-2024-10579 | MEDIUM | 4.3 | 0.4% | Nov 26, 2024 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access ... |
| CVE-2024-10308 | MEDIUM | 5.4 | 0.3% | Nov 26, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdow... |
| CVE-2024-11032 | MEDIUM | 6.1 | 0.4% | Nov 26, 2024 | The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg with... |
| CVE-2024-9170 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_produ... |
| CVE-2024-11192 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2024-11119 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' sh... |
| CVE-2024-11091 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-8772 | MEDIUM | 4.3 | 0.4% | Nov 26, 2024 | 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable ... |
| CVE-2024-6831 | MEDIUM | 4.4 | 0.2% | Nov 26, 2024 | Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove vie... |
| CVE-2024-34162 | MEDIUM | 5.3 | 0.8% | Nov 26, 2024 | The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But co... |
| CVE-2024-33616 | MEDIUM | 5.3 | 0.9% | Nov 26, 2024 | Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrat... |
| CVE-2024-32151 | MEDIUM | 5.9 | 1.3% | Nov 26, 2024 | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ... |
| CVE-2024-29978 | MEDIUM | 5.9 | 1.3% | Nov 26, 2024 | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ... |
| CVE-2024-29146 | MEDIUM | 5.9 | 0.9% | Nov 26, 2024 | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ... |
| CVE-2024-28955 | MEDIUM | 5.9 | 1.3% | Nov 26, 2024 | Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the ... |
| CVE-2024-11202 | MEDIUM | 6.1 | 0.6% | Nov 26, 2024 | Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in v... |
| CVE-2024-6749 | MEDIUM | 6.3 | 0.1% | Nov 26, 2024 | Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may exp... |
| CVE-2024-6476 | MEDIUM | 4.2 | 0.1% | Nov 26, 2024 | Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user ... |
| CVE-2024-11002 | MEDIUM | 6.3 | 0.6% | Nov 26, 2024 | The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_sh... |
| CVE-2024-10857 | MEDIUM | 6.5 | 0.8% | Nov 26, 2024 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to... |
| CVE-2024-10471 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now