2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47882 | MEDIUM | 6.1 | 0.5% | Oct 24, 2024 | OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went... |
| CVE-2024-47880 | MEDIUM | 6.9 | 0.4% | Oct 24, 2024 | OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command ca... |
| CVE-2024-47878 | MEDIUM | 6.1 | 0.4% | Oct 24, 2024 | OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/author... |
| CVE-2024-45259 | MEDIUM | 6.5 | 0.2% | Oct 24, 2024 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By inte... |
| CVE-2024-47173 | MEDIUM | 5.5 | 0.3% | Oct 24, 2024 | Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version ... |
| CVE-2024-46998 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Ed... |
| CVE-2024-46996 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Bl... |
| CVE-2024-46995 | MEDIUM | 6.1 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 4... |
| CVE-2024-46994 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog p... |
| CVE-2024-48442 | MEDIUM | 6.5 | 0.3% | Oct 24, 2024 | Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2... |
| CVE-2024-38314 | MEDIUM | 5.9 | 0.3% | Oct 24, 2024 | IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-... |
| CVE-2024-9692 | MEDIUM | 6.9 | 0.4% | Oct 24, 2024 | VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attack... |
| CVE-2024-48540 | MEDIUM | 6.2 | 0.2% | Oct 24, 2024 | Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code a... |
| CVE-2024-44205 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 an... |
| CVE-2024-44185 | MEDIUM | 5.5 | 0.3% | Oct 24, 2024 | The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma... |
| CVE-2024-44141 | MEDIUM | 6.8 | 0.2% | Oct 24, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A person with physical access to... |
| CVE-2024-40810 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An ... |
| CVE-2024-45031 | MEDIUM | 6.1 | 0.6% | Oct 24, 2024 | When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made i... |
| CVE-2024-49702 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred ... |
| CVE-2024-49696 | MEDIUM | 4.8 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gall... |
| CVE-2024-49695 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP ... |
| CVE-2024-49693 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega... |
| CVE-2024-10332 | MEDIUM | 6.1 | 0.2% | Oct 24, 2024 | A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacke... |
| CVE-2024-10180 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2024-8959 | MEDIUM | 6.4 | 0.4% | Oct 24, 2024 | The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored Cr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now