2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48955 | HIGH | 8.1 | 0.6% | Oct 29, 2024 | Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functi... |
| CVE-2024-9990 | HIGH | 8.8 | 0.3% | Oct 29, 2024 | The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This... |
| CVE-2024-8924 | HIGH | 7.5 | 0.5% | Oct 29, 2024 | ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability... |
| CVE-2024-50466 | HIGH | 8.8 | 0.2% | Oct 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkm... |
| CVE-2024-7985 | HIGH | 8.8 | 2.2% | Oct 29, 2024 | The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due ... |
| CVE-2024-49769 | HIGH | 7.5 | 1.4% | Oct 29, 2024 | Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before ... |
| CVE-2024-7962 | HIGH | 7.5 | 0.8% | Oct 29, 2024 | An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validatio... |
| CVE-2024-7807 | HIGH | 7.5 | 0.6% | Oct 29, 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploadi... |
| CVE-2024-7783 | HIGH | 7.5 | 0.3% | Oct 29, 2024 | mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password,... |
| CVE-2024-7474 | HIGH | 8.1 | 0.5% | Oct 29, 2024 | In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view o... |
| CVE-2024-6674 | HIGH | 7.1 | 0.2% | Oct 29, 2024 | A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information suc... |
| CVE-2024-41153 | HIGH | 7.2 | 1.6% | Oct 29, 2024 | Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of a... |
| CVE-2024-10467 | HIGH | 8.8 | 0.6% | Oct 29, 2024 | Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence ... |
| CVE-2024-10466 | HIGH | 7.5 | 0.8% | Oct 29, 2024 | By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to ... |
| CVE-2024-10459 | HIGH | 7.5 | 0.6% | Oct 29, 2024 | An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable cras... |
| CVE-2024-10458 | HIGH | 7.5 | 0.6% | Oct 29, 2024 | A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vu... |
| CVE-2024-49650 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xarbo BuddyPress G... |
| CVE-2024-49648 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafasashi SVG Capt... |
| CVE-2024-49647 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Carl Alberto Simpl... |
| CVE-2024-49646 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ioannup Code Gener... |
| CVE-2024-49678 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jinwen js a... |
| CVE-2024-10436 | HIGH | 8.8 | 0.7% | Oct 29, 2024 | The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,... |
| CVE-2024-50481 | HIGH | 8.8 | 0.4% | Oct 29, 2024 | Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege E... |
| CVE-2024-47401 | HIGH | 7.5 | 0.4% | Oct 29, 2024 | Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from b... |
| CVE-2024-22065 | HIGH | 8.8 | 1.2% | Oct 29, 2024 | There is a command injection vulnerability in ZTE MF258 Pro product. Due to insufficient validation of Ping Diagnosis in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now