2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43189 | MEDIUM | 5.9 | 0.3% | Nov 15, 2024 | IBM Concert Software 1.0.0 through 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the fa... |
| CVE-2024-41785 | MEDIUM | 6.1 | 0.3% | Nov 15, 2024 | IBM Concert Software 1.0.0 through 1.0.1 is vulnerable to cross-site scripting. This vulnerability allows an unauthentic... |
| CVE-2024-20373 | MEDIUM | 5.3 | 0.5% | Nov 15, 2024 | A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) fe... |
| CVE-2024-11243 | MEDIUM | 6.1 | 0.6% | Nov 15, 2024 | A vulnerability classified as problematic has been found in code-projects Online Shop Store 1.0. This affects an unknown... |
| CVE-2024-11240 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unk... |
| CVE-2024-11239 | MEDIUM | 4.3 | 1.5% | Nov 15, 2024 | A vulnerability has been found in Landray EKP up to 16.0 and classified as critical. This vulnerability affects the func... |
| CVE-2024-11238 | MEDIUM | 5.3 | 5.6% | Nov 15, 2024 | A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPre... |
| CVE-2024-1240 | MEDIUM | 6.1 | 0.3% | Nov 15, 2024 | An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling o... |
| CVE-2024-1097 | MEDIUM | 5.4 | 0.3% | Nov 15, 2024 | A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs... |
| CVE-2024-11182 | MEDIUM | 6.1 | 17.1% | Nov 15, 2024 | An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail messag... |
| CVE-2024-0875 | MEDIUM | 4.8 | 0.4% | Nov 15, 2024 | A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malici... |
| CVE-2024-0787 | MEDIUM | 5.9 | 0.5% | Nov 15, 2024 | phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwo... |
| CVE-2024-8979 | MEDIUM | 5.7 | 0.5% | Nov 15, 2024 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo... |
| CVE-2024-8978 | MEDIUM | 5.7 | 0.5% | Nov 15, 2024 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo... |
| CVE-2024-9529 | MEDIUM | 6.6 | 0.4% | Nov 15, 2024 | The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced C... |
| CVE-2024-8961 | MEDIUM | 5.4 | 0.3% | Nov 15, 2024 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo... |
| CVE-2024-10825 | MEDIUM | 6.1 | 0.3% | Nov 15, 2024 | The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ... |
| CVE-2024-10104 | MEDIUM | 5.9 | 0.3% | Nov 15, 2024 | The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high... |
| CVE-2024-9356 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | The Yotpo: Product & Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-42499 | MEDIUM | 5.3 | 0.6% | Nov 15, 2024 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior t... |
| CVE-2024-39610 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an... |
| CVE-2024-10793 | MEDIUM | 6.1 | 1.3% | Nov 15, 2024 | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all v... |
| CVE-2024-10582 | MEDIUM | 4.3 | 0.3% | Nov 15, 2024 | The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modifi... |
| CVE-2024-10260 | MEDIUM | 6.1 | 0.3% | Nov 15, 2024 | The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, a... |
| CVE-2024-10113 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now