2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6985 | MEDIUM | 4.4 | 0.4% | Oct 11, 2024 | A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnera... |
| CVE-2024-5474 | MEDIUM | 5.5 | 0.1% | Oct 11, 2024 | A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning softwar... |
| CVE-2024-47507 | MEDIUM | 6.9 | 0.3% | Oct 11, 2024 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne... |
| CVE-2024-47501 | MEDIUM | 6.8 | 0.2% | Oct 11, 2024 | A NULL Pointer Dereference vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX304, ... |
| CVE-2024-47496 | MEDIUM | 6.8 | 0.2% | Oct 11, 2024 | A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a loc... |
| CVE-2024-47489 | MEDIUM | 6.9 | 0.6% | Oct 11, 2024 | An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networ... |
| CVE-2024-39544 | MEDIUM | 5.1 | 0.2% | Oct 11, 2024 | An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved ... |
| CVE-2024-39534 | MEDIUM | 5.4 | 0.6% | Oct 11, 2024 | An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows ... |
| CVE-2024-39527 | MEDIUM | 6.8 | 0.2% | Oct 11, 2024 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Junip... |
| CVE-2024-47875 | MEDIUM | 6.1 | 1.1% | Oct 11, 2024 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to n... |
| CVE-2024-47830 | MEDIUM | 5.8 | 0.6% | Oct 11, 2024 | Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostn... |
| CVE-2024-25622 | MEDIUM | 4.3 | 0.4% | Oct 11, 2024 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers... |
| CVE-2024-8530 | MEDIUM | 5.9 | 0.5% | Oct 11, 2024 | CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data whe... |
| CVE-2024-6657 | MEDIUM | 6.5 | 0.2% | Oct 11, 2024 | A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuo... |
| CVE-2024-9856 | MEDIUM | 4.8 | 0.4% | Oct 11, 2024 | A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this ... |
| CVE-2024-9616 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the... |
| CVE-2024-9611 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site ... |
| CVE-2024-9610 | MEDIUM | 6.1 | 0.3% | Oct 11, 2024 | The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a... |
| CVE-2024-9587 | MEDIUM | 4.3 | 0.4% | Oct 11, 2024 | The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2024-9586 | MEDIUM | 5.3 | 0.4% | Oct 11, 2024 | The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2024-9543 | MEDIUM | 6.4 | 0.3% | Oct 11, 2024 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-9538 | MEDIUM | 6.5 | 0.4% | Oct 11, 2024 | The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2024-9507 | MEDIUM | 4.9 | 0.5% | Oct 11, 2024 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
| CVE-2024-9436 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner... |
| CVE-2024-9346 | MEDIUM | 6.1 | 0.3% | Oct 11, 2024 | The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' pa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now