2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28955 | MEDIUM | 5.9 | 1.3% | Nov 26, 2024 | Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the ... |
| CVE-2024-11202 | MEDIUM | 6.1 | 0.6% | Nov 26, 2024 | Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in v... |
| CVE-2024-6749 | MEDIUM | 6.3 | 0.1% | Nov 26, 2024 | Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may exp... |
| CVE-2024-6476 | MEDIUM | 4.2 | 0.1% | Nov 26, 2024 | Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user ... |
| CVE-2024-11002 | MEDIUM | 6.3 | 0.6% | Nov 26, 2024 | The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_sh... |
| CVE-2024-10857 | MEDIUM | 6.5 | 0.8% | Nov 26, 2024 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to... |
| CVE-2024-10471 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-53278 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin us... |
| CVE-2024-49353 | MEDIUM | 5.9 | 0.3% | Nov 26, 2024 | IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to re... |
| CVE-2024-49351 | MEDIUM | 5.5 | 0.1% | Nov 26, 2024 | IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user. |
| CVE-2024-11418 | MEDIUM | 6.1 | 0.3% | Nov 26, 2024 | The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th... |
| CVE-2024-11342 | MEDIUM | 6.1 | 0.2% | Nov 26, 2024 | The Skt NURCaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2024-49596 | MEDIUM | 6.5 | 0.4% | Nov 26, 2024 | Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged ... |
| CVE-2024-49595 | MEDIUM | 4.9 | 0.5% | Nov 26, 2024 | Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability... |
| CVE-2024-11678 | MEDIUM | 5.4 | 0.5% | Nov 26, 2024 | A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnera... |
| CVE-2024-11677 | MEDIUM | 5.4 | 0.5% | Nov 26, 2024 | A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affec... |
| CVE-2024-11676 | MEDIUM | 5.4 | 0.5% | Nov 26, 2024 | A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this is... |
| CVE-2024-11675 | MEDIUM | 5.4 | 0.5% | Nov 26, 2024 | A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by th... |
| CVE-2024-11673 | MEDIUM | 4.3 | 0.3% | Nov 25, 2024 | A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. T... |
| CVE-2024-53597 | MEDIUM | 6.3 | 0.3% | Nov 25, 2024 | masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit. |
| CVE-2024-53101 | MEDIUM | 5.5 | 0.2% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and ... |
| CVE-2024-53100 | MEDIUM | 4.7 | 0.2% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: nvme: tcp: avoid race between queue_lock lock and d... |
| CVE-2024-53097 | MEDIUM | 5.5 | 0.2% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: krealloc: Fix MTE false alarm in __do_krealloc ... |
| CVE-2024-53556 | MEDIUM | 6.1 | 0.3% | Nov 25, 2024 | An Open Redirect vulnerability in Taiga v6.8.1 allows attackers to redirect users to arbitrary websites via appending a ... |
| CVE-2024-50671 | MEDIUM | 4.3 | 0.3% | Nov 25, 2024 | Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now