2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47801 | MEDIUM | 6.1 | 0.3% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scr... |
| CVE-2024-47549 | MEDIUM | 6.1 | 0.3% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of uninte... |
| CVE-2024-45842 | MEDIUM | 5.3 | 0.5% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability.... |
| CVE-2024-10148 | MEDIUM | 5.4 | 0.2% | Oct 25, 2024 | The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in... |
| CVE-2024-9109 | MEDIUM | 4.3 | 0.4% | Oct 25, 2024 | The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modificat... |
| CVE-2024-9686 | MEDIUM | 5.3 | 0.3% | Oct 25, 2024 | The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a mis... |
| CVE-2024-10355 | MEDIUM | 4.9 | 1.0% | Oct 25, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0.... |
| CVE-2024-10354 | MEDIUM | 4.9 | 0.7% | Oct 25, 2024 | A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this... |
| CVE-2024-49762 | MEDIUM | 4.6 | 0.1% | Oct 24, 2024 | Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the ... |
| CVE-2024-49760 | MEDIUM | 5.3 | 0.6% | Oct 24, 2024 | OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter... |
| CVE-2024-49750 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak... |
| CVE-2024-49358 | MEDIUM | 5.3 | 0.5% | Oct 24, 2024 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all ... |
| CVE-2024-10348 | MEDIUM | 5.4 | 0.4% | Oct 24, 2024 | A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problemat... |
| CVE-2024-48932 | MEDIUM | 5.3 | 0.5% | Oct 24, 2024 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, ... |
| CVE-2024-48426 | MEDIUM | 6.2 | 0.2% | Oct 24, 2024 | A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz t... |
| CVE-2024-48425 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the... |
| CVE-2024-48424 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp... |
| CVE-2024-47882 | MEDIUM | 6.1 | 0.5% | Oct 24, 2024 | OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went... |
| CVE-2024-47880 | MEDIUM | 6.9 | 0.4% | Oct 24, 2024 | OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command ca... |
| CVE-2024-47878 | MEDIUM | 6.1 | 0.4% | Oct 24, 2024 | OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/author... |
| CVE-2024-45259 | MEDIUM | 6.5 | 0.2% | Oct 24, 2024 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By inte... |
| CVE-2024-47173 | MEDIUM | 5.5 | 0.3% | Oct 24, 2024 | Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version ... |
| CVE-2024-46998 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Ed... |
| CVE-2024-46996 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Bl... |
| CVE-2024-46995 | MEDIUM | 6.1 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 4... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now