2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9895 | MEDIUM | 5.4 | 0.3% | Oct 15, 2024 | The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo... |
| CVE-2024-47944 | MEDIUM | 6.8 | 0.4% | Oct 15, 2024 | The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin ... |
| CVE-2024-9944 | MEDIUM | 6.1 | 0.6% | Oct 15, 2024 | The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This i... |
| CVE-2024-21535 | MEDIUM | 6.1 | 0.5% | Oct 15, 2024 | Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property d... |
| CVE-2024-9969 | MEDIUM | 5.4 | 0.3% | Oct 15, 2024 | NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert ... |
| CVE-2024-9952 | MEDIUM | 4.8 | 0.4% | Oct 15, 2024 | A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects so... |
| CVE-2024-6757 | MEDIUM | 4.3 | 0.4% | Oct 15, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Ex... |
| CVE-2024-9548 | MEDIUM | 6.1 | 0.5% | Oct 15, 2024 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in a... |
| CVE-2024-9546 | MEDIUM | 5.3 | 0.5% | Oct 15, 2024 | The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to,... |
| CVE-2024-30117 | MEDIUM | 5.3 | 0.2% | Oct 14, 2024 | A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file unde... |
| CVE-2024-9953 | MEDIUM | 4.9 | 0.4% | Oct 14, 2024 | A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticate... |
| CVE-2024-35520 | MEDIUM | 6.8 | 9.1% | Oct 14, 2024 | Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter. |
| CVE-2024-35519 | MEDIUM | 6.8 | 1.0% | Oct 14, 2024 | Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in ... |
| CVE-2024-35518 | MEDIUM | 6.8 | 1.0% | Oct 14, 2024 | Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter. |
| CVE-2024-48821 | MEDIUM | 6.1 | 0.3% | Oct 14, 2024 | Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799... |
| CVE-2024-47885 | MEDIUM | 5.4 | 0.4% | Oct 14, 2024 | The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to ver... |
| CVE-2024-48795 | MEDIUM | 5.3 | 0.3% | Oct 14, 2024 | An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive info... |
| CVE-2024-48793 | MEDIUM | 5.9 | 0.3% | Oct 14, 2024 | An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware ... |
| CVE-2024-48790 | MEDIUM | 5.3 | 0.3% | Oct 14, 2024 | An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware ... |
| CVE-2024-47826 | MEDIUM | 6.1 | 0.3% | Oct 14, 2024 | eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows a... |
| CVE-2024-47767 | MEDIUM | 4.3 | 0.4% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-47766 | MEDIUM | 4.9 | 0.5% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-46988 | MEDIUM | 5.7 | 0.3% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-46980 | MEDIUM | 4.8 | 0.3% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-46528 | MEDIUM | 4.3 | 1.6% | Oct 14, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now