2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48192 | HIGH | 8 | 0.4% | Oct 17, 2024 | Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which a... |
| CVE-2024-10073 | HIGH | 7.5 | 0.5% | Oct 17, 2024 | A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function Clusteri... |
| CVE-2024-10072 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. This issue affects the function act... |
| CVE-2024-9414 | HIGH | 7 | 0.6% | Oct 17, 2024 | In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code... |
| CVE-2024-10071 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | A vulnerability classified as critical was found in ESAFENET CDG 5. This vulnerability affects the function actionUpdate... |
| CVE-2024-10070 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of t... |
| CVE-2024-10069 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function actio... |
| CVE-2024-6333 | HIGH | 7.2 | 1.2% | Oct 17, 2024 | Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products. |
| CVE-2024-49315 | HIGH | 8.6 | 0.6% | Oct 17, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD ... |
| CVE-2024-48048 | HIGH | 7.1 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in GabbyKhrmon Wsify Widget wsify-widget allows Stored XSS.This issue af... |
| CVE-2024-48032 | HIGH | 7.1 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sumitsurai Feature... |
| CVE-2024-48023 | HIGH | 7.1 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rconnect305 Restau... |
| CVE-2024-48021 | HIGH | 7.1 | 0.3% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Con... |
| CVE-2024-49320 | HIGH | 7.1 | 0.3% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dennis Encyclopedi... |
| CVE-2024-48043 | HIGH | 7.6 | 0.4% | Oct 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPi... |
| CVE-2024-48024 | HIGH | 7.5 | 0.4% | Oct 17, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Fahad Mahmood Keep Backup Da... |
| CVE-2024-10068 | HIGH | 8.5 | 0.2% | Oct 17, 2024 | A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an ... |
| CVE-2024-9184 | HIGH | 7.2 | 0.4% | Oct 17, 2024 | The SendPulse Free Web Push plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and... |
| CVE-2024-49391 | HIGH | 7.3 | 0.1% | Oct 17, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files ... |
| CVE-2024-49390 | HIGH | 7.3 | 0.2% | Oct 17, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files ... |
| CVE-2024-49389 | HIGH | 7.8 | 0.1% | Oct 17, 2024 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files ... |
| CVE-2024-5429 | HIGH | 7.6 | 0.5% | Oct 17, 2024 | The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputtin... |
| CVE-2024-9861 | HIGH | 8.1 | 0.6% | Oct 17, 2024 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up... |
| CVE-2024-9215 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu... |
| CVE-2024-45766 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code In... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now