2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10852 | MEDIUM | 4.3 | 0.4% | Nov 13, 2024 | The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil... |
| CVE-2024-10851 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o... |
| CVE-2024-10850 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to... |
| CVE-2024-10778 | MEDIUM | 4.3 | 0.5% | Nov 13, 2024 | The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all ve... |
| CVE-2024-10717 | MEDIUM | 6.5 | 0.4% | Nov 13, 2024 | The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a de... |
| CVE-2024-10577 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | The 胖鼠采集(Fat Rat Collect) 微信知乎简书腾讯新闻列表分页采集, 还有自动采集、自动发布、自动标签、等多项功能。开源插件 plugin for WordPress is vulnerable to Reflected ... |
| CVE-2024-10038 | MEDIUM | 6.1 | 0.3% | Nov 13, 2024 | The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to... |
| CVE-2024-28731 | MEDIUM | 4.3 | 0.2% | Nov 12, 2024 | Cross Site Request Forgery vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.3... |
| CVE-2024-28730 | MEDIUM | 5.4 | 0.3% | Nov 12, 2024 | Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME al... |
| CVE-2024-28728 | MEDIUM | 6.6 | 0.5% | Nov 12, 2024 | Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME al... |
| CVE-2024-48075 | MEDIUM | 5.3 | 0.6% | Nov 12, 2024 | A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier... |
| CVE-2024-11168 | MEDIUM | 6.3 | 0.7% | Nov 12, 2024 | The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that we... |
| CVE-2024-49512 | MEDIUM | 5.5 | 0.3% | Nov 12, 2024 | InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could le... |
| CVE-2024-49511 | MEDIUM | 5.5 | 0.3% | Nov 12, 2024 | InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could le... |
| CVE-2024-49510 | MEDIUM | 5.5 | 0.3% | Nov 12, 2024 | InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could le... |
| CVE-2024-11117 | MEDIUM | 4.3 | 0.3% | Nov 12, 2024 | Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass f... |
| CVE-2024-11116 | MEDIUM | 4.3 | 0.3% | Nov 12, 2024 | Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a ... |
| CVE-2024-11111 | MEDIUM | 4.3 | 0.3% | Nov 12, 2024 | Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced... |
| CVE-2024-11110 | MEDIUM | 6.5 | 0.3% | Nov 12, 2024 | Inappropriate implementation in Extensions in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass s... |
| CVE-2024-47440 | MEDIUM | 5.5 | 0.2% | Nov 12, 2024 | Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to... |
| CVE-2024-47439 | MEDIUM | 5.5 | 0.2% | Nov 12, 2024 | Substance3D - Painter versions 10.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could re... |
| CVE-2024-47438 | MEDIUM | 5.5 | 0.2% | Nov 12, 2024 | Substance3D - Painter versions 10.1.0 and earlier are affected by a Write-what-where Condition vulnerability that could ... |
| CVE-2024-47437 | MEDIUM | 5.5 | 0.2% | Nov 12, 2024 | Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to... |
| CVE-2024-47436 | MEDIUM | 5.5 | 0.2% | Nov 12, 2024 | Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to... |
| CVE-2024-47435 | MEDIUM | 5.5 | 0.2% | Nov 12, 2024 | Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now