2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49703 | MEDIUM | 6.5 | 0.2% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpE... |
| CVE-2024-49683 | MEDIUM | 5.3 | 0.3% | Oct 24, 2024 | Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp... |
| CVE-2024-49682 | MEDIUM | 6.1 | 0.3% | Oct 24, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allo... |
| CVE-2024-9650 | MEDIUM | 5.4 | 0.4% | Oct 24, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip’ parameter in all... |
| CVE-2024-9214 | MEDIUM | 6.1 | 0.4% | Oct 24, 2024 | The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-10176 | MEDIUM | 6.4 | 0.3% | Oct 24, 2024 | The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_embe... |
| CVE-2024-8312 | MEDIUM | 5.4 | 0.5% | Oct 24, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17... |
| CVE-2024-6826 | MEDIUM | 6.5 | 0.5% | Oct 24, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.... |
| CVE-2024-8717 | MEDIUM | 6.1 | 0.4% | Oct 24, 2024 | The PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip plugin for WordPress is vulnerable to Reflected Cross-Si... |
| CVE-2024-10050 | MEDIUM | 4.3 | 0.5% | Oct 24, 2024 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to... |
| CVE-2024-9943 | MEDIUM | 6.3 | 0.2% | Oct 24, 2024 | The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross... |
| CVE-2024-9531 | MEDIUM | 4.3 | 0.3% | Oct 24, 2024 | The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unaut... |
| CVE-2024-8667 | MEDIUM | 4.3 | 0.3% | Oct 24, 2024 | The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable ... |
| CVE-2024-9865 | MEDIUM | 6.1 | 0.4% | Oct 24, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-9864 | MEDIUM | 6.1 | 0.3% | Oct 24, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-40595 | MEDIUM | 5.3 | 0.2% | Oct 24, 2024 | An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise b... |
| CVE-2024-9374 | MEDIUM | 6.1 | 0.3% | Oct 24, 2024 | The Terms descriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_... |
| CVE-2024-48213 | MEDIUM | 4.3 | 0.6% | Oct 23, 2024 | RockOA v2.6.5 is vulnerable to Directory Traversal in webmain/system/beifen/beifenAction.php. |
| CVE-2024-40432 | MEDIUM | 6.5 | 0.4% | Oct 23, 2024 | A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IO... |
| CVE-2024-9949 | MEDIUM | 6.1 | 0.1% | Oct 23, 2024 | Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configura... |
| CVE-2024-20526 | MEDIUM | 5.3 | 0.5% | Oct 23, 2024 | A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, re... |
| CVE-2024-20493 | MEDIUM | 5.3 | 0.5% | Oct 23, 2024 | A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Securit... |
| CVE-2024-20485 | MEDIUM | 6.7 | 0.2% | Oct 23, 2024 | A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Def... |
| CVE-2024-20482 | MEDIUM | 6.5 | 0.5% | Oct 23, 2024 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl... |
| CVE-2024-20481 | MEDIUM | 5.8 | 15.9% | Oct 23, 2024 | A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco F... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now