2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49237 | MEDIUM | 6.1 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in ahmeti Ahmeti Wp Timeline ahmeti-wp-timeline allows Stored XSS.This i... |
| CVE-2024-49229 | MEDIUM | 6.1 | 0.3% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arifnezami Better ... |
| CVE-2024-49223 | MEDIUM | 6.1 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in shibulijack CJ Change Howdy cj-change-howdy allows Cross Site Request... |
| CVE-2024-49221 | MEDIUM | 6.1 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in julian.weinert cSlider cslider allows Cross Site Request Forgery.This... |
| CVE-2024-49220 | MEDIUM | 6.1 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Nikel Cookie Scanner cookie-scanner allows Cross Site Request Forgery... |
| CVE-2024-9683 | MEDIUM | 5.3 | 0.3% | Oct 17, 2024 | A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is prov... |
| CVE-2024-47459 | MEDIUM | 5.5 | 0.2% | Oct 17, 2024 | Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead ... |
| CVE-2024-49580 | MEDIUM | 5.3 | 0.3% | Oct 17, 2024 | In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure |
| CVE-2024-49579 | MEDIUM | 6.1 | 0.4% | Oct 17, 2024 | In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized... |
| CVE-2024-48046 | MEDIUM | 5.9 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact ... |
| CVE-2024-48037 | MEDIUM | 5.4 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Si... |
| CVE-2024-48036 | MEDIUM | 5.4 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT B... |
| CVE-2024-48031 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in sumitsurai Featured Posts with Multiple Custom Groups (FPMCG) feature... |
| CVE-2024-48025 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dogrow Simple Base... |
| CVE-2024-48022 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SysBasics S... |
| CVE-2024-48047 | MEDIUM | 4.3 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Razon Komar Pal Linked Variation for WooCommerce linked-variation-for... |
| CVE-2024-48038 | MEDIUM | 4.3 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in tuxlog wp-Monalisa wp-monalisa.This issue affects wp-Monalisa: from n... |
| CVE-2024-9898 | MEDIUM | 5.4 | 0.4% | Oct 17, 2024 | The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dd-parallax shortc... |
| CVE-2024-45713 | MEDIUM | 4.4 | 0.4% | Oct 17, 2024 | SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been... |
| CVE-2024-8920 | MEDIUM | 6.4 | 0.4% | Oct 17, 2024 | The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo... |
| CVE-2024-49392 | MEDIUM | 4.8 | 0.2% | Oct 17, 2024 | Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acro... |
| CVE-2024-49386 | MEDIUM | 5.7 | 0.2% | Oct 17, 2024 | Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows... |
| CVE-2024-9951 | MEDIUM | 6.1 | 0.3% | Oct 17, 2024 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' paramete... |
| CVE-2024-3187 | MEDIUM | 5.9 | 0.5% | Oct 17, 2024 | This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6.... |
| CVE-2024-3186 | MEDIUM | 5.3 | 0.4% | Oct 17, 2024 | CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now