2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20269 | MEDIUM | 5.4 | 0.4% | Oct 23, 2024 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an... |
| CVE-2024-20264 | MEDIUM | 5.4 | 0.4% | Oct 23, 2024 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an... |
| CVE-2024-49676 | MEDIUM | 6.6 | 0.3% | Oct 23, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Michael Bourne Custom Icons for Elementor custom-icons-... |
| CVE-2024-30124 | MEDIUM | 4 | 0.2% | Oct 23, 2024 | HCL Sametime is impacted by insecure services in-use on the UIM client by default. An unused legacy REST service was ena... |
| CVE-2024-5764 | MEDIUM | 6.5 | 0.4% | Oct 23, 2024 | Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for... |
| CVE-2024-49370 | MEDIUM | 4.9 | 0.5% | Oct 23, 2024 | Pimcore is an open source data and experience management platform. When a PortalUserObject is connected to a PimcoreUser... |
| CVE-2024-30122 | MEDIUM | 5.3 | 0.2% | Oct 23, 2024 | HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were m... |
| CVE-2024-50050 | MEDIUM | 6.3 | 0.9% | Oct 23, 2024 | Llama Stack prior to revision 7a8aa775e5a267cf8660d83140011a0b7f91e005 used pickle as a serialization format for socket ... |
| CVE-2024-10250 | MEDIUM | 6.1 | 0.3% | Oct 23, 2024 | The Nioland theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s’ parameter in all versions up... |
| CVE-2024-10041 | MEDIUM | 4.7 | 0.3% | Oct 23, 2024 | A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim ... |
| CVE-2024-10289 | MEDIUM | 6.1 | 0.3% | Oct 23, 2024 | Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially ... |
| CVE-2024-10288 | MEDIUM | 6.1 | 0.3% | Oct 23, 2024 | Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially ... |
| CVE-2024-10287 | MEDIUM | 6.1 | 0.3% | Oct 23, 2024 | Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially ... |
| CVE-2024-10286 | MEDIUM | 6.1 | 0.3% | Oct 23, 2024 | Cross-Site Scripting (XSS) vulnerability affecting LocalServer 1.0.9 that could allow a remote user to send a specially ... |
| CVE-2024-8500 | MEDIUM | 5.4 | 0.4% | Oct 23, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-10276 | MEDIUM | 6.1 | 0.4% | Oct 23, 2024 | A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability ... |
| CVE-2024-9530 | MEDIUM | 4.3 | 0.4% | Oct 23, 2024 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2024-10045 | MEDIUM | 4.3 | 0.2% | Oct 23, 2024 | The Transients Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-9583 | MEDIUM | 5.4 | 0.4% | Oct 23, 2024 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauth... |
| CVE-2024-9829 | MEDIUM | 6.5 | 0.4% | Oct 23, 2024 | The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks... |
| CVE-2024-31880 | MEDIUM | 6.5 | 0.4% | Oct 23, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv... |
| CVE-2024-48656 | MEDIUM | 4.8 | 0.4% | Oct 22, 2024 | Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker... |
| CVE-2024-48652 | MEDIUM | 4.8 | 1.0% | Oct 22, 2024 | Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the cont... |
| CVE-2024-48644 | MEDIUM | 5.3 | 0.7% | Oct 22, 2024 | Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_230... |
| CVE-2024-48415 | MEDIUM | 5 | 0.4% | Oct 22, 2024 | itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastna... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now