2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7424 | MEDIUM | 5.4 | 0.3% | Nov 1, 2024 | The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access t... |
| CVE-2024-49501 | MEDIUM | 5.7 | 0.2% | Nov 1, 2024 | Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is ... |
| CVE-2024-21510 | MEDIUM | 5.4 | 0.5% | Nov 1, 2024 | Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the... |
| CVE-2024-10620 | MEDIUM | 6.9 | 0.5% | Nov 1, 2024 | A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part... |
| CVE-2024-10605 | MEDIUM | 6.5 | 0.4% | Nov 1, 2024 | A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This... |
| CVE-2024-6480 | MEDIUM | 5.4 | 0.3% | Oct 31, 2024 | The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_... |
| CVE-2024-6479 | MEDIUM | 6.5 | 0.5% | Oct 31, 2024 | The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' at... |
| CVE-2024-10598 | MEDIUM | 6.5 | 0.5% | Oct 31, 2024 | A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unkno... |
| CVE-2024-50802 | MEDIUM | 6 | 0.4% | Oct 31, 2024 | A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controlle... |
| CVE-2024-50801 | MEDIUM | 6 | 0.4% | Oct 31, 2024 | A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controlle... |
| CVE-2024-10573 | MEDIUM | 6.7 | 0.3% | Oct 31, 2024 | An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may writ... |
| CVE-2024-50347 | MEDIUM | 6.3 | 0.3% | Oct 31, 2024 | Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is a... |
| CVE-2024-51430 | MEDIUM | 6.4 | 0.5% | Oct 31, 2024 | Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker t... |
| CVE-2024-50354 | MEDIUM | 5.5 | 0.3% | Oct 31, 2024 | gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deseriali... |
| CVE-2024-8553 | MEDIUM | 6.3 | 0.4% | Oct 31, 2024 | A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authent... |
| CVE-2024-8934 | MEDIUM | 6.5 | 0.2% | Oct 31, 2024 | A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI)... |
| CVE-2024-10454 | MEDIUM | 6.1 | 0.2% | Oct 31, 2024 | Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerabilit... |
| CVE-2024-43933 | MEDIUM | 4.3 | 0.3% | Oct 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.Ap... |
| CVE-2024-43930 | MEDIUM | 4.3 | 0.2% | Oct 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects... |
| CVE-2024-30149 | MEDIUM | 6.5 | 0.2% | Oct 31, 2024 | HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable. |
| CVE-2024-9446 | MEDIUM | 6.4 | 0.3% | Oct 31, 2024 | The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor ... |
| CVE-2024-9434 | MEDIUM | 6.1 | 0.2% | Oct 31, 2024 | The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2024-9430 | MEDIUM | 5.3 | 0.4% | Oct 31, 2024 | The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized acces... |
| CVE-2024-9165 | MEDIUM | 6.4 | 0.3% | Oct 31, 2024 | The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-9700 | MEDIUM | 5.3 | 0.4% | Oct 31, 2024 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure D... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now