2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32946 | MEDIUM | 5.9 | 0.3% | Oct 30, 2024 | A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitte... |
| CVE-2024-3935 | MEDIUM | 6.5 | 0.8% | Oct 30, 2024 | In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridg... |
| CVE-2024-9388 | MEDIUM | 5.4 | 0.3% | Oct 30, 2024 | The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i... |
| CVE-2024-50512 | MEDIUM | 5.3 | 0.3% | Oct 30, 2024 | Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping posti-shipping allows... |
| CVE-2024-8444 | MEDIUM | 5.4 | 0.3% | Oct 30, 2024 | The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross... |
| CVE-2024-10223 | MEDIUM | 6.4 | 0.3% | Oct 30, 2024 | The WP Team – WordPress Team Member Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
| CVE-2024-8871 | MEDIUM | 6.1 | 0.4% | Oct 30, 2024 | The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scr... |
| CVE-2024-10399 | MEDIUM | 4.3 | 0.4% | Oct 30, 2024 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2024-9886 | MEDIUM | 6.4 | 0.3% | Oct 30, 2024 | The WP Baidu Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'baidu_map' shortcod... |
| CVE-2024-9885 | MEDIUM | 6.4 | 0.3% | Oct 30, 2024 | The Widget or Sidebar Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'side... |
| CVE-2024-9884 | MEDIUM | 6.4 | 0.3% | Oct 30, 2024 | The T(-) Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tminus' shortcode... |
| CVE-2024-8792 | MEDIUM | 6.1 | 0.4% | Oct 30, 2024 | The Subscribe to Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que... |
| CVE-2024-8627 | MEDIUM | 5.4 | 0.3% | Oct 30, 2024 | The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all ... |
| CVE-2024-10503 | MEDIUM | 6.1 | 0.3% | Oct 30, 2024 | A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some ... |
| CVE-2024-50348 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | InstantCMS is a free and open source content management system. In photo upload function in the photo album page there i... |
| CVE-2024-50454 | MEDIUM | 5.3 | 0.3% | Oct 29, 2024 | Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce... |
| CVE-2024-50425 | MEDIUM | 6.5 | 0.4% | Oct 29, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roland Murg WP Booking Syste... |
| CVE-2024-50424 | MEDIUM | 6.5 | 0.4% | Oct 29, 2024 | Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access... |
| CVE-2024-50423 | MEDIUM | 5.4 | 0.4% | Oct 29, 2024 | Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access... |
| CVE-2024-50422 | MEDIUM | 5.3 | 0.5% | Oct 29, 2024 | Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2024-50421 | MEDIUM | 5.3 | 0.4% | Oct 29, 2024 | Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-pa... |
| CVE-2024-48572 | MEDIUM | 5.3 | 0.4% | Oct 29, 2024 | A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addres... |
| CVE-2024-48461 | MEDIUM | 4.8 | 0.4% | Oct 29, 2024 | Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitr... |
| CVE-2024-10491 | MEDIUM | 5.3 | 0.4% | Oct 29, 2024 | A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in... |
| CVE-2024-25566 | MEDIUM | 6.1 | 0.2% | Oct 29, 2024 | An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect UR... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now