2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11493 | MEDIUM | 6.1 | 0.4% | Nov 20, 2024 | A vulnerability classified as problematic was found in 115cms up to 20240807. This vulnerability affects unknown code of... |
| CVE-2024-11492 | MEDIUM | 6.1 | 0.4% | Nov 20, 2024 | A vulnerability classified as problematic has been found in 115cms up to 20240807. This affects an unknown part of the f... |
| CVE-2024-52796 | MEDIUM | 5.3 | 0.5% | Nov 20, 2024 | Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable... |
| CVE-2024-52725 | MEDIUM | 4.9 | 0.5% | Nov 20, 2024 | SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code v... |
| CVE-2024-11491 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | A vulnerability was found in 115cms up to 20240807. It has been rated as problematic. Affected by this issue is some unk... |
| CVE-2024-11490 | MEDIUM | 6.1 | 0.3% | Nov 20, 2024 | A vulnerability was found in 115cms up to 20240807. It has been declared as problematic. Affected by this vulnerability ... |
| CVE-2024-11489 | MEDIUM | 6.1 | 0.3% | Nov 20, 2024 | A vulnerability was found in 115cms up to 20240807. It has been classified as problematic. Affected is an unknown functi... |
| CVE-2024-11488 | MEDIUM | 6.1 | 0.3% | Nov 20, 2024 | A vulnerability was found in 115cms up to 20240807 and classified as problematic. This issue affects some unknown proces... |
| CVE-2024-11486 | MEDIUM | 4.3 | 0.3% | Nov 20, 2024 | A vulnerability, which was classified as problematic, was found in Code4Berry Decoration Management System 1.0. This aff... |
| CVE-2024-52471 | MEDIUM | 6.1 | 0.3% | Nov 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in petesheppar... |
| CVE-2024-51209 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to... |
| CVE-2024-52597 | MEDIUM | 6.1 | 0.4% | Nov 20, 2024 | 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Versions prior... |
| CVE-2024-11154 | MEDIUM | 4.3 | 0.4% | Nov 20, 2024 | The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner... |
| CVE-2024-11406 | MEDIUM | 6.9 | 0.5% | Nov 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS ... |
| CVE-2024-11404 | MEDIUM | 5.5 | 0.3% | Nov 20, 2024 | Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basi... |
| CVE-2024-10520 | MEDIUM | 5.3 | 0.3% | Nov 20, 2024 | The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili... |
| CVE-2024-48899 | MEDIUM | 4.3 | 0.3% | Nov 20, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course ba... |
| CVE-2024-45691 | MEDIUM | 5.4 | 0.4% | Nov 20, 2024 | A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be byp... |
| CVE-2024-45689 | MEDIUM | 6.5 | 0.3% | Nov 20, 2024 | A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability... |
| CVE-2024-10872 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-c... |
| CVE-2024-11179 | MEDIUM | 6.5 | 0.4% | Nov 20, 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via t... |
| CVE-2024-10891 | MEDIUM | 6.4 | 0.3% | Nov 20, 2024 | The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's... |
| CVE-2024-10665 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data d... |
| CVE-2024-11176 | MEDIUM | 5.3 | 0.4% | Nov 20, 2024 | Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access o... |
| CVE-2024-10126 | MEDIUM | 4.3 | 0.4% | Nov 20, 2024 | Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now