2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45124 | MEDIUM | 5.3 | 0.6% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v... |
| CVE-2024-45123 | MEDIUM | 6.1 | 0.4% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scrip... |
| CVE-2024-45122 | MEDIUM | 4.3 | 0.5% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v... |
| CVE-2024-45121 | MEDIUM | 4.3 | 0.5% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v... |
| CVE-2024-45119 | MEDIUM | 4.9 | 0.8% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forg... |
| CVE-2024-45118 | MEDIUM | 6.5 | 0.6% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v... |
| CVE-2024-22068 | MEDIUM | 6.5 | 0.2% | Oct 10, 2024 | Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 6... |
| CVE-2024-9802 | MEDIUM | 5.3 | 0.2% | Oct 10, 2024 | The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The respons... |
| CVE-2024-9798 | MEDIUM | 5.3 | 0.2% | Oct 10, 2024 | The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for at... |
| CVE-2024-7049 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending ... |
| CVE-2024-9780 | MEDIUM | 5.5 | 0.2% | Oct 10, 2024 | ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file |
| CVE-2024-9520 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing ... |
| CVE-2024-9074 | MEDIUM | 5.4 | 0.2% | Oct 10, 2024 | The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve... |
| CVE-2024-9067 | MEDIUM | 4.3 | 0.3% | Oct 10, 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
| CVE-2024-8477 | MEDIUM | 4.3 | 0.2% | Oct 10, 2024 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab... |
| CVE-2024-9685 | MEDIUM | 4.3 | 0.3% | Oct 10, 2024 | The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing c... |
| CVE-2024-9457 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up... |
| CVE-2024-9377 | MEDIUM | 6.1 | 0.4% | Oct 10, 2024 | The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Script... |
| CVE-2024-9205 | MEDIUM | 6.1 | 0.3% | Oct 10, 2024 | The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t... |
| CVE-2024-9072 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File... |
| CVE-2024-9066 | MEDIUM | 5.4 | 0.2% | Oct 10, 2024 | The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ... |
| CVE-2024-9065 | MEDIUM | 5.3 | 0.4% | Oct 10, 2024 | The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-9064 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v... |
| CVE-2024-9057 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2024-8987 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now