2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9708 | MEDIUM | 5.4 | 0.3% | Oct 31, 2024 | The Easy SVG Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2024-10544 | MEDIUM | 5.3 | 0.5% | Oct 31, 2024 | The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2024-10557 | MEDIUM | 6.5 | 0.6% | Oct 31, 2024 | A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected... |
| CVE-2024-10086 | MEDIUM | 6.1 | 0.4% | Oct 30, 2024 | A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Co... |
| CVE-2024-10006 | MEDIUM | 5.8 | 0.5% | Oct 30, 2024 | A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentio... |
| CVE-2024-10005 | MEDIUM | 5.8 | 0.7% | Oct 30, 2024 | A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intent... |
| CVE-2024-51419 | MEDIUM | 6.1 | 0.3% | Oct 30, 2024 | Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibiti... |
| CVE-2024-51242 | MEDIUM | 6.5 | 0.4% | Oct 30, 2024 | A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployControl... |
| CVE-2024-48807 | MEDIUM | 5.4 | 0.3% | Oct 30, 2024 | Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to e... |
| CVE-2024-48346 | MEDIUM | 6.1 | 0.2% | Oct 30, 2024 | xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerab... |
| CVE-2024-43382 | MEDIUM | 5.9 | 0.2% | Oct 30, 2024 | Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being u... |
| CVE-2024-48272 | MEDIUM | 6.5 | 0.6% | Oct 30, 2024 | D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers t... |
| CVE-2024-10546 | MEDIUM | 6.3 | 0.3% | Oct 30, 2024 | A vulnerability classified as critical was found in open-scratch Teaching 在线教学平台 up to 2.7. This vulnerability affects u... |
| CVE-2024-46531 | MEDIUM | 6.3 | 0.3% | Oct 30, 2024 | phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchi... |
| CVE-2024-48648 | MEDIUM | 6.1 | 0.3% | Oct 30, 2024 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attacker... |
| CVE-2024-48569 | MEDIUM | 5.4 | 0.5% | Oct 30, 2024 | Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edi... |
| CVE-2024-48241 | MEDIUM | 5.5 | 0.2% | Oct 30, 2024 | An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function... |
| CVE-2024-31975 | MEDIUM | 4.8 | 0.3% | Oct 30, 2024 | EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID para... |
| CVE-2024-31973 | MEDIUM | 5.2 | 0.5% | Oct 30, 2024 | Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS... |
| CVE-2024-31972 | MEDIUM | 4.3 | 0.4% | Oct 30, 2024 | EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary J... |
| CVE-2024-9110 | MEDIUM | 6.1 | 0.2% | Oct 30, 2024 | A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform re... |
| CVE-2024-50344 | MEDIUM | 4.6 | 0.3% | Oct 30, 2024 | I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browse... |
| CVE-2024-50353 | MEDIUM | 5.3 | 0.3% | Oct 30, 2024 | ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files ... |
| CVE-2024-33626 | MEDIUM | 5.3 | 0.4% | Oct 30, 2024 | The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure ... |
| CVE-2024-33603 | MEDIUM | 5.3 | 8.8% | Oct 30, 2024 | The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenti... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now