2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10045 | MEDIUM | 4.3 | 0.2% | Oct 23, 2024 | The Transients Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-9583 | MEDIUM | 5.4 | 0.4% | Oct 23, 2024 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauth... |
| CVE-2024-9829 | MEDIUM | 6.5 | 0.4% | Oct 23, 2024 | The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks... |
| CVE-2024-31880 | MEDIUM | 6.5 | 0.4% | Oct 23, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv... |
| CVE-2024-48656 | MEDIUM | 4.8 | 0.4% | Oct 22, 2024 | Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker... |
| CVE-2024-48652 | MEDIUM | 4.8 | 1.0% | Oct 22, 2024 | Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the cont... |
| CVE-2024-48644 | MEDIUM | 5.3 | 0.7% | Oct 22, 2024 | Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_230... |
| CVE-2024-48415 | MEDIUM | 5 | 0.4% | Oct 22, 2024 | itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastna... |
| CVE-2024-45526 | MEDIUM | 5.3 | 0.5% | Oct 22, 2024 | An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send r... |
| CVE-2024-46903 | MEDIUM | 6.5 | 1.2% | Oct 22, 2024 | A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose... |
| CVE-2024-45335 | MEDIUM | 5.5 | 0.2% | Oct 22, 2024 | Trend Micro Antivirus One, version 3.10.4 and below contains a vulnerability that could allow an attacker to use a speci... |
| CVE-2024-10183 | MEDIUM | 5.2 | 0.1% | Oct 22, 2024 | A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges t... |
| CVE-2024-49211 | MEDIUM | 6.1 | 0.3% | Oct 22, 2024 | Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.0... |
| CVE-2024-49210 | MEDIUM | 6.1 | 0.3% | Oct 22, 2024 | Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A r... |
| CVE-2024-49209 | MEDIUM | 4.3 | 0.3% | Oct 22, 2024 | Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to suppo... |
| CVE-2024-48708 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action ... |
| CVE-2024-48707 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit wi... |
| CVE-2024-48706 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform wi... |
| CVE-2024-46538 | MEDIUM | 4.8 | 77.9% | Oct 22, 2024 | A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2024-49373 | MEDIUM | 4.3 | 0.4% | Oct 22, 2024 | No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an a... |
| CVE-2024-48929 | MEDIUM | 4.2 | 0.2% | Oct 22, 2024 | Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and ver... |
| CVE-2024-48927 | MEDIUM | 4.6 | 0.4% | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.... |
| CVE-2024-48925 | MEDIUM | 6.5 | 0.4% | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version... |
| CVE-2024-46240 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/co... |
| CVE-2024-8980 | MEDIUM | 6.1 | 0.2% | Oct 22, 2024 | The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA throug... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now