2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10883 | MEDIUM | 6.1 | 0.4% | Nov 16, 2024 | The SimpleForm – Contact form made simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th... |
| CVE-2024-10875 | MEDIUM | 6.1 | 0.4% | Nov 16, 2024 | The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_... |
| CVE-2024-10533 | MEDIUM | 4.3 | 0.4% | Nov 16, 2024 | The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check... |
| CVE-2024-10262 | MEDIUM | 6.3 | 0.6% | Nov 16, 2024 | The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and... |
| CVE-2024-10147 | MEDIUM | 6.4 | 0.3% | Nov 16, 2024 | The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versio... |
| CVE-2024-10017 | MEDIUM | 6.4 | 0.3% | Nov 16, 2024 | The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2024-10015 | MEDIUM | 6.4 | 0.8% | Nov 16, 2024 | The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and '... |
| CVE-2024-10861 | MEDIUM | 5.3 | 0.4% | Nov 16, 2024 | The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2024-10795 | MEDIUM | 4.3 | 0.3% | Nov 16, 2024 | The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2... |
| CVE-2024-10786 | MEDIUM | 4.3 | 0.3% | Nov 16, 2024 | The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capabil... |
| CVE-2024-51765 | MEDIUM | 5.5 | 0.1% | Nov 15, 2024 | A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, ... |
| CVE-2024-51764 | MEDIUM | 5.5 | 0.1% | Nov 15, 2024 | A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configura... |
| CVE-2024-50983 | MEDIUM | 5.4 | 0.3% | Nov 15, 2024 | FlightPath 7.5 contains a Cross Site Scripting (XSS) vulnerability, which allows authenticated remote attackers with adm... |
| CVE-2024-11261 | MEDIUM | 6.1 | 0.3% | Nov 15, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Student Record Management System 1.0. Aff... |
| CVE-2024-49592 | MEDIUM | 6.7 | 0.2% | Nov 15, 2024 | Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation ... |
| CVE-2024-45611 | MEDIUM | 5.4 | 0.3% | Nov 15, 2024 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2024-45610 | MEDIUM | 6.1 | 0.3% | Nov 15, 2024 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2024-11217 | MEDIUM | 4.9 | 0.4% | Nov 15, 2024 | A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug hig... |
| CVE-2024-49536 | MEDIUM | 5.5 | 0.2% | Nov 15, 2024 | Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disc... |
| CVE-2024-45609 | MEDIUM | 6.1 | 0.3% | Nov 15, 2024 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2024-3334 | MEDIUM | 4.3 | 0.1% | Nov 15, 2024 | A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agen... |
| CVE-2024-24459 | MEDIUM | 5.9 | 0.3% | Nov 15, 2024 | An invalid memory access when handling the ProtocolIE_ID field of S1Setup Request messages in Athonet vEPC MME v11.4.0 a... |
| CVE-2024-24458 | MEDIUM | 5.9 | 0.3% | Nov 15, 2024 | An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Ath... |
| CVE-2024-24457 | MEDIUM | 5.9 | 0.3% | Nov 15, 2024 | An invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEP... |
| CVE-2024-24455 | MEDIUM | 5.9 | 0.3% | Nov 15, 2024 | An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now