2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51514 | MEDIUM | 5.5 | 0.1% | Nov 5, 2024 | Vulnerability of pop-up windows belonging to no app in the VPN module Impact: Successful exploitation of this vulnerabi... |
| CVE-2024-51513 | MEDIUM | 5.5 | 0.1% | Nov 5, 2024 | Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerab... |
| CVE-2024-51512 | MEDIUM | 5.5 | 0.1% | Nov 5, 2024 | Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulne... |
| CVE-2024-51511 | MEDIUM | 5.5 | 0.1% | Nov 5, 2024 | Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulne... |
| CVE-2024-51510 | MEDIUM | 5.5 | 0.1% | Nov 5, 2024 | Out-of-bounds access vulnerability in the logo module Impact: Successful exploitation of this vulnerability may affect s... |
| CVE-2024-47402 | MEDIUM | 5.5 | 0.1% | Nov 5, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
| CVE-2024-9883 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-9689 | MEDIUM | 4.3 | 0.2% | Nov 5, 2024 | The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow at... |
| CVE-2024-7877 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not... |
| CVE-2024-7876 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not... |
| CVE-2024-5578 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-10807 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue aff... |
| CVE-2024-10340 | MEDIUM | 6.4 | 0.3% | Nov 5, 2024 | The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'scu' short... |
| CVE-2024-10806 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulner... |
| CVE-2024-51498 | MEDIUM | 6 | 0.5% | Nov 5, 2024 | cobalt is a media downloader that doesn't piss you off. A malicious cobalt instance could serve links with the `javascri... |
| CVE-2024-50346 | MEDIUM | 5.1 | 0.6% | Nov 5, 2024 | WebFeed is a lightweight web feed reader extension for Firefox/Chrome. Multiple HTML injection vulnerabilities in WebFee... |
| CVE-2024-32870 | MEDIUM | 5.8 | 0.7% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and ... |
| CVE-2024-31448 | MEDIUM | 6.1 | 0.3% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-sit... |
| CVE-2024-51502 | MEDIUM | 5.1 | 0.5% | Nov 4, 2024 | loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the ... |
| CVE-2024-48059 | MEDIUM | 6.1 | 0.3% | Nov 4, 2024 | gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket s... |
| CVE-2024-48057 | MEDIUM | 6.1 | 0.2% | Nov 4, 2024 | localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriat... |
| CVE-2024-48052 | MEDIUM | 6.5 | 0.5% | Nov 4, 2024 | In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The re... |
| CVE-2024-48463 | MEDIUM | 6.5 | 0.6% | Nov 4, 2024 | Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within th... |
| CVE-2024-45185 | MEDIUM | 5.1 | 0.2% | Nov 4, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108... |
| CVE-2024-45086 | MEDIUM | 5.5 | 0.4% | Nov 4, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when process... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now