2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9898 | MEDIUM | 5.4 | 0.4% | Oct 17, 2024 | The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dd-parallax shortc... |
| CVE-2024-45713 | MEDIUM | 4.4 | 0.4% | Oct 17, 2024 | SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been... |
| CVE-2024-8920 | MEDIUM | 6.4 | 0.4% | Oct 17, 2024 | The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo... |
| CVE-2024-49392 | MEDIUM | 4.8 | 0.2% | Oct 17, 2024 | Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acro... |
| CVE-2024-49386 | MEDIUM | 5.7 | 0.2% | Oct 17, 2024 | Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows... |
| CVE-2024-9951 | MEDIUM | 6.1 | 0.3% | Oct 17, 2024 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' paramete... |
| CVE-2024-3187 | MEDIUM | 5.9 | 0.5% | Oct 17, 2024 | This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6.... |
| CVE-2024-3186 | MEDIUM | 5.3 | 0.4% | Oct 17, 2024 | CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when ... |
| CVE-2024-3184 | MEDIUM | 5.9 | 0.5% | Oct 17, 2024 | Multiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when comp... |
| CVE-2024-9213 | MEDIUM | 6.1 | 0.4% | Oct 17, 2024 | The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du... |
| CVE-2024-9352 | MEDIUM | 4.3 | 0.2% | Oct 17, 2024 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site... |
| CVE-2024-9351 | MEDIUM | 4.3 | 0.2% | Oct 17, 2024 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site... |
| CVE-2024-9347 | MEDIUM | 6.1 | 0.5% | Oct 17, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi... |
| CVE-2024-8719 | MEDIUM | 6.1 | 0.3% | Oct 17, 2024 | The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like... |
| CVE-2024-7417 | MEDIUM | 4.3 | 0.4% | Oct 17, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t... |
| CVE-2024-49593 | MEDIUM | 5.3 | 0.5% | Oct 17, 2024 | In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the ... |
| CVE-2024-9940 | MEDIUM | 4.3 | 0.4% | Oct 17, 2024 | The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.... |
| CVE-2024-9240 | MEDIUM | 6.1 | 0.4% | Oct 17, 2024 | The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a... |
| CVE-2024-45767 | MEDIUM | 6.5 | 0.3% | Oct 17, 2024 | Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used... |
| CVE-2024-48758 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the compone... |
| CVE-2024-47889 | MEDIUM | 6.6 | 0.9% | Oct 16, 2024 | Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9... |
| CVE-2024-47888 | MEDIUM | 6.6 | 1.0% | Oct 16, 2024 | Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.... |
| CVE-2024-46212 | MEDIUM | 4.9 | 0.9% | Oct 16, 2024 | An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory tr... |
| CVE-2024-44762 | MEDIUM | 5.3 | 2.5% | Oct 16, 2024 | A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid ... |
| CVE-2024-47887 | MEDIUM | 6.6 | 1.0% | Oct 16, 2024 | Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now