2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52033 | MEDIUM | 5.3 | 0.4% | Nov 20, 2024 | Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware ver... |
| CVE-2024-47865 | MEDIUM | 5.3 | 0.4% | Nov 20, 2024 | Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earli... |
| CVE-2024-9239 | MEDIUM | 6.1 | 0.4% | Nov 20, 2024 | The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q... |
| CVE-2024-8726 | MEDIUM | 6.1 | 0.3% | Nov 20, 2024 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ... |
| CVE-2024-11277 | MEDIUM | 6.1 | 0.3% | Nov 20, 2024 | The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, an... |
| CVE-2024-10365 | MEDIUM | 4.3 | 0.3% | Nov 20, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-9653 | MEDIUM | 6.1 | 0.3% | Nov 20, 2024 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Sit... |
| CVE-2024-52614 | MEDIUM | 4 | 0.2% | Nov 20, 2024 | Use of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions pri... |
| CVE-2024-11278 | MEDIUM | 6.1 | 0.4% | Nov 20, 2024 | The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu... |
| CVE-2024-44309 | MEDIUM | 6.3 | 21.0% | Nov 20, 2024 | A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2... |
| CVE-2024-52595 | MEDIUM | 6.1 | 0.5% | Nov 19, 2024 | lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, th... |
| CVE-2024-52392 | MEDIUM | 6.5 | 0.2% | Nov 19, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in w3speedster W3SPEEDSTER w3speedster-wp.This issue affects W3SPEEDSTER... |
| CVE-2024-30424 | MEDIUM | 5.4 | 0.2% | Nov 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Beaver Buil... |
| CVE-2024-11400 | MEDIUM | 6.1 | 0.3% | Nov 19, 2024 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2024-52763 | MEDIUM | 5.4 | 0.6% | Nov 19, 2024 | A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows ... |
| CVE-2024-52762 | MEDIUM | 5.4 | 0.8% | Nov 19, 2024 | A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows atta... |
| CVE-2024-45420 | MEDIUM | 6.5 | 0.4% | Nov 19, 2024 | Uncontrolled resource consumption in some Zoom Apps before version 6.2.0 may allow an authenticated user to conduct a de... |
| CVE-2024-37070 | MEDIUM | 6.5 | 0.3% | Nov 19, 2024 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to obtain sensitive information ... |
| CVE-2024-50430 | MEDIUM | 4.8 | 0.3% | Nov 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Bea... |
| CVE-2024-53088 | MEDIUM | 4.7 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: i40e: fix race condition by adding filter's interme... |
| CVE-2024-53087 | MEDIUM | 5.5 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix possible exec queue leak in exec IOCTL ... |
| CVE-2024-53086 | MEDIUM | 5.5 | 0.1% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Drop VM dma-resv lock on xe_sync_in_fence_g... |
| CVE-2024-53085 | MEDIUM | 5.5 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: tpm: Lock TPM chip in tpm_pm_suspend() first Setti... |
| CVE-2024-53084 | MEDIUM | 5.5 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Break an object reference loop Wh... |
| CVE-2024-53083 | MEDIUM | 5.5 | 0.2% | Nov 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic: init value of hdr_len/txbuf_... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now