2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50312 | MEDIUM | 5.3 | 0.5% | Oct 22, 2024 | A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allow... |
| CVE-2024-50311 | MEDIUM | 6.5 | 0.6% | Oct 22, 2024 | A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batchi... |
| CVE-2024-9231 | MEDIUM | 6.1 | 0.4% | Oct 22, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ... |
| CVE-2024-10189 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-9591 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | The Category and Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_category_ima... |
| CVE-2024-9590 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image me... |
| CVE-2024-9589 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_met... |
| CVE-2024-9588 | MEDIUM | 5.4 | 0.2% | Oct 22, 2024 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to... |
| CVE-2024-9541 | MEDIUM | 4.3 | 0.3% | Oct 22, 2024 | The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to... |
| CVE-2024-8852 | MEDIUM | 5.3 | 1.2% | Oct 22, 2024 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi... |
| CVE-2024-10003 | MEDIUM | 6.3 | 0.4% | Oct 22, 2024 | The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing... |
| CVE-2024-47224 | MEDIUM | 6.5 | 0.3% | Oct 21, 2024 | A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.20... |
| CVE-2024-41712 | MEDIUM | 6.6 | 0.5% | Oct 21, 2024 | A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacke... |
| CVE-2024-40091 | MEDIUM | 5.3 | 0.4% | Oct 21, 2024 | Vilo 5 Mesh WiFi System <= 5.16.1.33 lacks authentication in the Boa webserver, which allows remote, unauthenticated att... |
| CVE-2024-40090 | MEDIUM | 4.3 | 0.3% | Oct 21, 2024 | Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Information Disclosure. An information leak in the Boa webserver a... |
| CVE-2024-40088 | MEDIUM | 5.3 | 0.7% | Oct 21, 2024 | A Directory Traversal vulnerability in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthen... |
| CVE-2024-35315 | MEDIUM | 5.6 | 0.8% | Oct 21, 2024 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instanc... |
| CVE-2024-35287 | MEDIUM | 6.7 | 0.2% | Oct 21, 2024 | A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow... |
| CVE-2024-30160 | MEDIUM | 4.8 | 0.3% | Oct 21, 2024 | A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenti... |
| CVE-2024-30159 | MEDIUM | 4.8 | 0.3% | Oct 21, 2024 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attac... |
| CVE-2024-50065 | MEDIUM | 5.5 | 0.2% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: ntfs3: Change to non-blocking allocation in ntfs_d_... |
| CVE-2024-50064 | MEDIUM | 5.5 | 0.2% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: zram: free secondary algorithms names We need to k... |
| CVE-2024-50062 | MEDIUM | 5.5 | 0.2% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Avoid null pointer deref during path... |
| CVE-2024-50060 | MEDIUM | 5.5 | 0.2% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: io_uring: check if we need to reschedule during ove... |
| CVE-2024-50058 | MEDIUM | 5.5 | 0.2% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: serial: protect uart_port_dtr_rts() in uart_shutdow... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now