2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49632 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Senthil Vel CWD 3D... |
| CVE-2024-47640 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp ... |
| CVE-2024-10226 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcod... |
| CVE-2024-8143 | MEDIUM | 4.3 | 0.5% | Oct 29, 2024 | In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authen... |
| CVE-2024-7473 | MEDIUM | 6.5 | 0.4% | Oct 29, 2024 | An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions ... |
| CVE-2024-7472 | MEDIUM | 6.5 | 0.4% | Oct 29, 2024 | lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-ve... |
| CVE-2024-7010 | MEDIUM | 5.9 | 0.5% | Oct 29, 2024 | mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to c... |
| CVE-2024-6673 | MEDIUM | 6.5 | 0.2% | Oct 29, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` fi... |
| CVE-2024-51181 | MEDIUM | 6.1 | 0.4% | Oct 29, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code ... |
| CVE-2024-51180 | MEDIUM | 6.1 | 0.4% | Oct 29, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/index.php in PHPGurukul IFSC Code Finder P... |
| CVE-2024-49645 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilias Gomatos Affi... |
| CVE-2024-49643 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fifthsegment White... |
| CVE-2024-49641 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tidaweb Tida URL S... |
| CVE-2024-49640 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AmaderCode Lab ACL... |
| CVE-2024-49639 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Stoever Mon... |
| CVE-2024-49638 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ventureharbour Ris... |
| CVE-2024-49637 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foxskav Bet WC 201... |
| CVE-2024-49636 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woracal Agile Vide... |
| CVE-2024-49635 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in manjurul.cis Banne... |
| CVE-2024-10474 | MEDIUM | 6.5 | 0.3% | Oct 29, 2024 | Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in link... |
| CVE-2024-10468 | MEDIUM | 5.3 | 0.4% | Oct 29, 2024 | Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. ... |
| CVE-2024-10465 | MEDIUM | 6.5 | 0.5% | Oct 29, 2024 | A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox... |
| CVE-2024-10464 | MEDIUM | 6.5 | 0.6% | Oct 29, 2024 | Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the brows... |
| CVE-2024-10463 | MEDIUM | 6.5 | 0.7% | Oct 29, 2024 | Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefo... |
| CVE-2024-10462 | MEDIUM | 6.5 | 0.5% | Oct 29, 2024 | Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox <... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now