2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8729 | MEDIUM | 6.1 | 0.3% | Oct 10, 2024 | The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add... |
| CVE-2024-8513 | MEDIUM | 5.3 | 0.4% | Oct 10, 2024 | The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable... |
| CVE-2024-7048 | MEDIUM | 5.4 | 0.4% | Oct 10, 2024 | In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/... |
| CVE-2024-48942 | MEDIUM | 5.9 | 0.5% | Oct 10, 2024 | The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to eas... |
| CVE-2024-48941 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to byp... |
| CVE-2024-8264 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent... |
| CVE-2024-48933 | MEDIUM | 6.1 | 0.3% | Oct 9, 2024 | A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary we... |
| CVE-2024-7041 | MEDIUM | 6.5 | 0.4% | Oct 9, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerabili... |
| CVE-2024-38818 | MEDIUM | 6.7 | 0.3% | Oct 9, 2024 | VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vuln... |
| CVE-2024-38817 | MEDIUM | 6.7 | 0.5% | Oct 9, 2024 | VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may ... |
| CVE-2024-38815 | MEDIUM | 4.3 | 0.3% | Oct 9, 2024 | VMware NSX contains a content spoofing vulnerability. An unauthenticated malicious actor may be able to craft a URL an... |
| CVE-2024-30118 | MEDIUM | 5.7 | 0.3% | Oct 9, 2024 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in... |
| CVE-2024-47833 | MEDIUM | 6.5 | 0.2% | Oct 9, 2024 | Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine lear... |
| CVE-2024-47828 | MEDIUM | 6.5 | 0.3% | Oct 9, 2024 | ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to de... |
| CVE-2024-47816 | MEDIUM | 6.4 | 0.3% | Oct 9, 2024 | ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the ... |
| CVE-2024-47815 | MEDIUM | 6 | 0.4% | Oct 9, 2024 | IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a var... |
| CVE-2024-47812 | MEDIUM | 6 | 0.4% | Oct 9, 2024 | ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface st... |
| CVE-2024-47763 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with st... |
| CVE-2024-9471 | MEDIUM | 4.7 | 0.3% | Oct 9, 2024 | A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated ... |
| CVE-2024-9470 | MEDIUM | 5.3 | 0.4% | Oct 9, 2024 | A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view th... |
| CVE-2024-9469 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with W... |
| CVE-2024-9467 | MEDIUM | 6.1 | 0.6% | Oct 9, 2024 | A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context ... |
| CVE-2024-9466 | MEDIUM | 6.5 | 11.2% | Oct 9, 2024 | A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated atta... |
| CVE-2024-9464 | MEDIUM | 6.5 | 81.7% | Oct 9, 2024 | An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary... |
| CVE-2024-42988 | MEDIUM | 4.3 | 0.3% | Oct 9, 2024 | Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows auth... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now