2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45526 | MEDIUM | 5.3 | 0.5% | Oct 22, 2024 | An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send r... |
| CVE-2024-46903 | MEDIUM | 6.5 | 1.2% | Oct 22, 2024 | A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose... |
| CVE-2024-45335 | MEDIUM | 5.5 | 0.2% | Oct 22, 2024 | Trend Micro Antivirus One, version 3.10.4 and below contains a vulnerability that could allow an attacker to use a speci... |
| CVE-2024-10183 | MEDIUM | 5.2 | 0.1% | Oct 22, 2024 | A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges t... |
| CVE-2024-49211 | MEDIUM | 6.1 | 0.3% | Oct 22, 2024 | Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.0... |
| CVE-2024-49210 | MEDIUM | 6.1 | 0.3% | Oct 22, 2024 | Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A r... |
| CVE-2024-49209 | MEDIUM | 4.3 | 0.3% | Oct 22, 2024 | Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to suppo... |
| CVE-2024-48708 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action ... |
| CVE-2024-48707 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit wi... |
| CVE-2024-48706 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform wi... |
| CVE-2024-46538 | MEDIUM | 4.8 | 77.9% | Oct 22, 2024 | A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2024-49373 | MEDIUM | 4.3 | 0.4% | Oct 22, 2024 | No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an a... |
| CVE-2024-48929 | MEDIUM | 4.2 | 0.2% | Oct 22, 2024 | Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and ver... |
| CVE-2024-48927 | MEDIUM | 4.6 | 0.4% | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.... |
| CVE-2024-48925 | MEDIUM | 6.5 | 0.4% | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version... |
| CVE-2024-46240 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/co... |
| CVE-2024-8980 | MEDIUM | 6.1 | 0.2% | Oct 22, 2024 | The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA throug... |
| CVE-2024-50312 | MEDIUM | 5.3 | 0.5% | Oct 22, 2024 | A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allow... |
| CVE-2024-50311 | MEDIUM | 6.5 | 0.6% | Oct 22, 2024 | A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batchi... |
| CVE-2024-9231 | MEDIUM | 6.1 | 0.4% | Oct 22, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ... |
| CVE-2024-10189 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-9591 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | The Category and Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_category_ima... |
| CVE-2024-9590 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image me... |
| CVE-2024-9589 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_met... |
| CVE-2024-9588 | MEDIUM | 5.4 | 0.2% | Oct 22, 2024 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now