2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3184 | MEDIUM | 5.9 | 0.5% | Oct 17, 2024 | Multiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when comp... |
| CVE-2024-9213 | MEDIUM | 6.1 | 0.4% | Oct 17, 2024 | The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du... |
| CVE-2024-9352 | MEDIUM | 4.3 | 0.2% | Oct 17, 2024 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site... |
| CVE-2024-9351 | MEDIUM | 4.3 | 0.2% | Oct 17, 2024 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site... |
| CVE-2024-9347 | MEDIUM | 6.1 | 0.5% | Oct 17, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi... |
| CVE-2024-8719 | MEDIUM | 6.1 | 0.3% | Oct 17, 2024 | The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like... |
| CVE-2024-7417 | MEDIUM | 4.3 | 0.4% | Oct 17, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t... |
| CVE-2024-49593 | MEDIUM | 5.3 | 0.5% | Oct 17, 2024 | In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the ... |
| CVE-2024-9940 | MEDIUM | 4.3 | 0.4% | Oct 17, 2024 | The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.... |
| CVE-2024-9240 | MEDIUM | 6.1 | 0.4% | Oct 17, 2024 | The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a... |
| CVE-2024-45767 | MEDIUM | 6.5 | 0.3% | Oct 17, 2024 | Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used... |
| CVE-2024-48758 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the compone... |
| CVE-2024-47889 | MEDIUM | 6.6 | 0.9% | Oct 16, 2024 | Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9... |
| CVE-2024-47888 | MEDIUM | 6.6 | 1.0% | Oct 16, 2024 | Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.... |
| CVE-2024-46212 | MEDIUM | 4.9 | 0.9% | Oct 16, 2024 | An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory tr... |
| CVE-2024-44762 | MEDIUM | 5.3 | 2.5% | Oct 16, 2024 | A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid ... |
| CVE-2024-47887 | MEDIUM | 6.6 | 1.0% | Oct 16, 2024 | Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions ... |
| CVE-2024-47836 | MEDIUM | 4.3 | 0.5% | Oct 16, 2024 | Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability all... |
| CVE-2024-45796 | MEDIUM | 5.3 | 0.5% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-41128 | MEDIUM | 6.6 | 1.1% | Oct 16, 2024 | Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions ... |
| CVE-2024-9143 | MEDIUM | 4.3 | 6.0% | Oct 16, 2024 | Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial ... |
| CVE-2024-46606 | MEDIUM | 5.4 | 0.4% | Oct 16, 2024 | A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to ... |
| CVE-2024-46605 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to ... |
| CVE-2024-45072 | MEDIUM | 5.5 | 0.4% | Oct 16, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when process... |
| CVE-2024-45071 | MEDIUM | 4.8 | 0.2% | Oct 16, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now