2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50472 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in martindrapeau Amil... |
| CVE-2024-50471 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in checklistcom Trip ... |
| CVE-2024-50470 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themes4WP Themes4W... |
| CVE-2024-50465 | MEDIUM | 6.5 | 0.4% | Oct 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP SEO – Calin Vin... |
| CVE-2024-50463 | MEDIUM | 6.1 | 0.3% | Oct 28, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-phot... |
| CVE-2024-50307 | MEDIUM | 5.5 | 0.3% | Oct 28, 2024 | Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If... |
| CVE-2024-48936 | MEDIUM | 5 | 0.3% | Oct 28, 2024 | SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit a... |
| CVE-2024-10435 | MEDIUM | 6.3 | 1.2% | Oct 28, 2024 | A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown... |
| CVE-2024-50624 | MEDIUM | 5.9 | 0.3% | Oct 28, 2024 | ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled m... |
| CVE-2024-10433 | MEDIUM | 6.1 | 0.4% | Oct 28, 2024 | A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affecte... |
| CVE-2024-50615 | MEDIUM | 6.5 | 0.4% | Oct 27, 2024 | TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp... |
| CVE-2024-50614 | MEDIUM | 6.5 | 0.4% | Oct 27, 2024 | TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XM... |
| CVE-2024-50613 | MEDIUM | 6.5 | 0.5% | Oct 27, 2024 | libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encod... |
| CVE-2024-50612 | MEDIUM | 5.5 | 0.3% | Oct 27, 2024 | libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read. |
| CVE-2024-10419 | MEDIUM | 6.1 | 0.4% | Oct 27, 2024 | A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as problematic. Affected ... |
| CVE-2024-10414 | MEDIUM | 4.8 | 0.4% | Oct 27, 2024 | A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an... |
| CVE-2024-10412 | MEDIUM | 5.4 | 0.4% | Oct 27, 2024 | A vulnerability was found in Poco-z Guns-Medical 1.0. It has been declared as problematic. Affected by this vulnerabilit... |
| CVE-2024-50602 | MEDIUM | 5.9 | 1.0% | Oct 27, 2024 | An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_Stop... |
| CVE-2024-10117 | MEDIUM | 5.4 | 0.4% | Oct 26, 2024 | The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate short... |
| CVE-2024-9116 | MEDIUM | 6.4 | 0.3% | Oct 26, 2024 | The Monkee-Boy Essentials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ... |
| CVE-2024-10357 | MEDIUM | 4.3 | 0.4% | Oct 26, 2024 | The Clever Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up ... |
| CVE-2024-9967 | MEDIUM | 5.4 | 0.3% | Oct 26, 2024 | The WP show more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_more shortcode ... |
| CVE-2024-9853 | MEDIUM | 6.4 | 0.3% | Oct 26, 2024 | The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions... |
| CVE-2024-9642 | MEDIUM | 6.4 | 0.3% | Oct 26, 2024 | The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i... |
| CVE-2024-10092 | MEDIUM | 4.3 | 0.4% | Oct 26, 2024 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now