2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8526 | MEDIUM | 5.9 | 0.6% | Nov 21, 2024 | A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when vis... |
| CVE-2024-45514 | MEDIUM | 5.4 | 0.6% | Nov 21, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists i... |
| CVE-2024-45512 | MEDIUM | 5.4 | 0.4% | Nov 21, 2024 | An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerabilit... |
| CVE-2024-48747 | MEDIUM | 6.8 | 0.9% | Nov 21, 2024 | An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file. |
| CVE-2024-7130 | MEDIUM | 5.5 | 0.4% | Nov 21, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Comput... |
| CVE-2024-53426 | MEDIUM | 6.2 | 0.3% | Nov 21, 2024 | A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function. |
| CVE-2024-53425 | MEDIUM | 6.2 | 0.3% | Nov 21, 2024 | A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue oc... |
| CVE-2024-11089 | MEDIUM | 5.3 | 0.6% | Nov 21, 2024 | The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2024-7016 | MEDIUM | 4.8 | 0.4% | Nov 21, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Smarttek In... |
| CVE-2024-11587 | MEDIUM | 6.1 | 0.9% | Nov 21, 2024 | A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOption... |
| CVE-2024-9851 | MEDIUM | 5.4 | 0.4% | Nov 21, 2024 | The LSX Tour Operator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers... |
| CVE-2024-9828 | MEDIUM | 4.1 | 0.5% | Nov 21, 2024 | The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it... |
| CVE-2024-9768 | MEDIUM | 4.8 | 0.4% | Nov 21, 2024 | The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-9600 | MEDIUM | 4.8 | 0.4% | Nov 21, 2024 | The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-9542 | MEDIUM | 4.3 | 0.3% | Nov 21, 2024 | The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,... |
| CVE-2024-9442 | MEDIUM | 5.4 | 0.4% | Nov 21, 2024 | The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2024-9371 | MEDIUM | 6.1 | 0.5% | Nov 21, 2024 | The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-... |
| CVE-2024-9111 | MEDIUM | 6.4 | 0.5% | Nov 21, 2024 | The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi... |
| CVE-2024-8157 | MEDIUM | 4.3 | 0.2% | Nov 21, 2024 | The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which... |
| CVE-2024-5029 | MEDIUM | 4.8 | 0.2% | Nov 21, 2024 | The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is miss... |
| CVE-2024-52067 | MEDIUM | 4.9 | 0.7% | Nov 21, 2024 | Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context valu... |
| CVE-2024-11596 | MEDIUM | 5.5 | 0.3% | Nov 21, 2024 | ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or cra... |
| CVE-2024-11595 | MEDIUM | 5.5 | 0.3% | Nov 21, 2024 | FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet in... |
| CVE-2024-11456 | MEDIUM | 6.1 | 0.4% | Nov 21, 2024 | The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2024-11455 | MEDIUM | 6.4 | 0.4% | Nov 21, 2024 | The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-ma... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now