2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11308 | MEDIUM | 5.5 | 0.2% | Nov 18, 2024 | The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore th... |
| CVE-2024-52926 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent. |
| CVE-2024-52922 | MEDIUM | 6.5 | 0.3% | Nov 18, 2024 | In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes... |
| CVE-2024-52921 | MEDIUM | 5.3 | 0.4% | Nov 18, 2024 | In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block. |
| CVE-2024-52919 | MEDIUM | 6.5 | 0.3% | Nov 18, 2024 | Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via ... |
| CVE-2024-52918 | MEDIUM | 6.5 | 0.5% | Nov 18, 2024 | Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and ap... |
| CVE-2024-52917 | MEDIUM | 6.5 | 0.3% | Nov 18, 2024 | Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received ... |
| CVE-2024-52913 | MEDIUM | 5.3 | 0.4% | Nov 18, 2024 | In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because ... |
| CVE-2024-38828 | MEDIUM | 5.3 | 0.7% | Nov 18, 2024 | Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack. |
| CVE-2024-11306 | MEDIUM | 6.9 | 0.5% | Nov 18, 2024 | A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. Th... |
| CVE-2024-11305 | MEDIUM | 6.3 | 3.7% | Nov 18, 2024 | A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability ... |
| CVE-2024-52386 | MEDIUM | 5.3 | 0.5% | Nov 16, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-11094 | MEDIUM | 5.3 | 0.4% | Nov 16, 2024 | The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2024-10592 | MEDIUM | 6.4 | 0.8% | Nov 16, 2024 | The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in a... |
| CVE-2024-10614 | MEDIUM | 4.3 | 0.3% | Nov 16, 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabili... |
| CVE-2024-9938 | MEDIUM | 6.1 | 0.4% | Nov 16, 2024 | The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame... |
| CVE-2024-9850 | MEDIUM | 6.4 | 0.3% | Nov 16, 2024 | The SVG Case Study plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all version... |
| CVE-2024-9615 | MEDIUM | 6.1 | 0.4% | Nov 16, 2024 | The BulkPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho... |
| CVE-2024-9386 | MEDIUM | 6.4 | 0.4% | Nov 16, 2024 | The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-8873 | MEDIUM | 6.1 | 0.5% | Nov 16, 2024 | The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th... |
| CVE-2024-6628 | MEDIUM | 4.3 | 0.2% | Nov 16, 2024 | The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site R... |
| CVE-2024-11118 | MEDIUM | 5.3 | 0.3% | Nov 16, 2024 | The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2024-11092 | MEDIUM | 6.4 | 0.3% | Nov 16, 2024 | The SVGPlus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versi... |
| CVE-2024-11085 | MEDIUM | 5.4 | 0.3% | Nov 16, 2024 | The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability ch... |
| CVE-2024-10884 | MEDIUM | 6.1 | 0.4% | Nov 16, 2024 | The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now