2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9628 | MEDIUM | 6.5 | 0.3% | Oct 25, 2024 | The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a ... |
| CVE-2024-47158 | MEDIUM | 5.4 | 0.2% | Oct 25, 2024 | N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary co... |
| CVE-2024-10342 | MEDIUM | 5.4 | 0.3% | Oct 25, 2024 | The League of Legends Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in ver... |
| CVE-2024-10341 | MEDIUM | 6.5 | 0.4% | Oct 25, 2024 | The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versi... |
| CVE-2024-10150 | MEDIUM | 5.4 | 0.3% | Oct 25, 2024 | The Bamazoo – Button Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dgs sh... |
| CVE-2024-9607 | MEDIUM | 6.1 | 0.3% | Oct 25, 2024 | The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu... |
| CVE-2024-50583 | MEDIUM | 6.3 | 0.3% | Oct 25, 2024 | Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to impr... |
| CVE-2024-48870 | MEDIUM | 4.8 | 0.3% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scr... |
| CVE-2024-47801 | MEDIUM | 6.1 | 0.3% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scr... |
| CVE-2024-47549 | MEDIUM | 6.1 | 0.3% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of uninte... |
| CVE-2024-45842 | MEDIUM | 5.3 | 0.5% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability.... |
| CVE-2024-10148 | MEDIUM | 5.4 | 0.2% | Oct 25, 2024 | The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in... |
| CVE-2024-9109 | MEDIUM | 4.3 | 0.4% | Oct 25, 2024 | The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modificat... |
| CVE-2024-9686 | MEDIUM | 5.3 | 0.3% | Oct 25, 2024 | The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a mis... |
| CVE-2024-10355 | MEDIUM | 4.9 | 1.0% | Oct 25, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0.... |
| CVE-2024-10354 | MEDIUM | 4.9 | 0.7% | Oct 25, 2024 | A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this... |
| CVE-2024-49762 | MEDIUM | 4.6 | 0.1% | Oct 24, 2024 | Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the ... |
| CVE-2024-49760 | MEDIUM | 5.3 | 0.6% | Oct 24, 2024 | OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter... |
| CVE-2024-49750 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak... |
| CVE-2024-49358 | MEDIUM | 5.3 | 0.5% | Oct 24, 2024 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all ... |
| CVE-2024-10348 | MEDIUM | 5.4 | 0.4% | Oct 24, 2024 | A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problemat... |
| CVE-2024-48932 | MEDIUM | 5.3 | 0.5% | Oct 24, 2024 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, ... |
| CVE-2024-48426 | MEDIUM | 6.2 | 0.2% | Oct 24, 2024 | A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz t... |
| CVE-2024-48425 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the... |
| CVE-2024-48424 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now