2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45461 | MEDIUM | 6.3 | 0.7% | Oct 16, 2024 | The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources,... |
| CVE-2024-9582 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an ac... |
| CVE-2024-8918 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and inc... |
| CVE-2024-9937 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramete... |
| CVE-2024-9888 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-9873 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordP... |
| CVE-2024-9891 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due... |
| CVE-2024-9652 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all... |
| CVE-2024-9649 | MEDIUM | 4.3 | 0.2% | Oct 16, 2024 | The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request For... |
| CVE-2024-9647 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all version... |
| CVE-2024-9521 | MEDIUM | 6.4 | 0.3% | Oct 16, 2024 | The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and i... |
| CVE-2024-9104 | MEDIUM | 5.6 | 0.3% | Oct 16, 2024 | The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. ... |
| CVE-2024-8787 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of... |
| CVE-2024-8541 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin fo... |
| CVE-2024-38204 | MEDIUM | 6.5 | 1.0% | Oct 15, 2024 | Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. |
| CVE-2024-9966 | MEDIUM | 5.3 | 0.3% | Oct 15, 2024 | Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass ... |
| CVE-2024-9964 | MEDIUM | 4.3 | 0.3% | Oct 15, 2024 | Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced... |
| CVE-2024-9963 | MEDIUM | 4.3 | 0.3% | Oct 15, 2024 | Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convince... |
| CVE-2024-9962 | MEDIUM | 4.3 | 0.3% | Oct 15, 2024 | Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convin... |
| CVE-2024-9958 | MEDIUM | 4.3 | 0.3% | Oct 15, 2024 | Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to pe... |
| CVE-2024-48714 | MEDIUM | 6.5 | 0.4% | Oct 15, 2024 | In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which... |
| CVE-2024-48713 | MEDIUM | 6.5 | 0.4% | Oct 15, 2024 | In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, whi... |
| CVE-2024-48712 | MEDIUM | 6.5 | 0.4% | Oct 15, 2024 | In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can... |
| CVE-2024-48710 | MEDIUM | 6.5 | 0.4% | Oct 15, 2024 | In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, wh... |
| CVE-2024-31955 | MEDIUM | 4.9 | 0.2% | Oct 15, 2024 | An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fau... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now