2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46994 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog p... |
| CVE-2024-48442 | MEDIUM | 6.5 | 0.3% | Oct 24, 2024 | Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2... |
| CVE-2024-38314 | MEDIUM | 5.9 | 0.3% | Oct 24, 2024 | IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-... |
| CVE-2024-9692 | MEDIUM | 6.9 | 0.4% | Oct 24, 2024 | VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attack... |
| CVE-2024-48540 | MEDIUM | 6.2 | 0.2% | Oct 24, 2024 | Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code a... |
| CVE-2024-44205 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 an... |
| CVE-2024-44185 | MEDIUM | 5.5 | 0.3% | Oct 24, 2024 | The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma... |
| CVE-2024-44141 | MEDIUM | 6.8 | 0.2% | Oct 24, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A person with physical access to... |
| CVE-2024-40810 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An ... |
| CVE-2024-45031 | MEDIUM | 6.1 | 0.6% | Oct 24, 2024 | When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made i... |
| CVE-2024-49702 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred ... |
| CVE-2024-49696 | MEDIUM | 4.8 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gall... |
| CVE-2024-49695 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP ... |
| CVE-2024-49693 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega... |
| CVE-2024-10332 | MEDIUM | 6.1 | 0.2% | Oct 24, 2024 | A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacke... |
| CVE-2024-10180 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2024-8959 | MEDIUM | 6.4 | 0.4% | Oct 24, 2024 | The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-49703 | MEDIUM | 6.5 | 0.2% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpE... |
| CVE-2024-49683 | MEDIUM | 5.3 | 0.3% | Oct 24, 2024 | Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp... |
| CVE-2024-49682 | MEDIUM | 6.1 | 0.3% | Oct 24, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allo... |
| CVE-2024-9650 | MEDIUM | 5.4 | 0.4% | Oct 24, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip’ parameter in all... |
| CVE-2024-9214 | MEDIUM | 6.1 | 0.4% | Oct 24, 2024 | The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-10176 | MEDIUM | 6.4 | 0.3% | Oct 24, 2024 | The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_embe... |
| CVE-2024-8312 | MEDIUM | 5.4 | 0.5% | Oct 24, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17... |
| CVE-2024-6826 | MEDIUM | 6.5 | 0.5% | Oct 24, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now