2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22034 | MEDIUM | 5.5 | 0.2% | Oct 16, 2024 | Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker t... |
| CVE-2024-22033 | MEDIUM | 6.3 | 0.9% | Oct 16, 2024 | The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide... |
| CVE-2024-6380 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX... |
| CVE-2024-8921 | MEDIUM | 6.4 | 0.4% | Oct 16, 2024 | The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i... |
| CVE-2024-9444 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up... |
| CVE-2024-9540 | MEDIUM | 4.3 | 0.4% | Oct 16, 2024 | The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2024-45715 | MEDIUM | 5.2 | 0.3% | Oct 16, 2024 | The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to exis... |
| CVE-2024-45714 | MEDIUM | 4.1 | 0.8% | Oct 16, 2024 | Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a v... |
| CVE-2024-45461 | MEDIUM | 6.3 | 0.7% | Oct 16, 2024 | The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources,... |
| CVE-2024-9582 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an ac... |
| CVE-2024-8918 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and inc... |
| CVE-2024-9937 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramete... |
| CVE-2024-9888 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-9873 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordP... |
| CVE-2024-9891 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due... |
| CVE-2024-9652 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all... |
| CVE-2024-9649 | MEDIUM | 4.3 | 0.2% | Oct 16, 2024 | The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request For... |
| CVE-2024-9647 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all version... |
| CVE-2024-9521 | MEDIUM | 6.4 | 0.3% | Oct 16, 2024 | The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and i... |
| CVE-2024-9104 | MEDIUM | 5.6 | 0.3% | Oct 16, 2024 | The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. ... |
| CVE-2024-8787 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of... |
| CVE-2024-8541 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin fo... |
| CVE-2024-38204 | MEDIUM | 6.5 | 1.0% | Oct 15, 2024 | Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. |
| CVE-2024-9966 | MEDIUM | 5.3 | 0.3% | Oct 15, 2024 | Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass ... |
| CVE-2024-9964 | MEDIUM | 4.3 | 0.3% | Oct 15, 2024 | Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now