2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9798 | MEDIUM | 5.3 | 0.2% | Oct 10, 2024 | The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for at... |
| CVE-2024-9780 | MEDIUM | 5.5 | 0.2% | Oct 10, 2024 | ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file |
| CVE-2024-9520 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing ... |
| CVE-2024-9074 | MEDIUM | 5.4 | 0.2% | Oct 10, 2024 | The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve... |
| CVE-2024-9067 | MEDIUM | 4.3 | 0.3% | Oct 10, 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
| CVE-2024-8477 | MEDIUM | 4.3 | 0.2% | Oct 10, 2024 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab... |
| CVE-2024-9685 | MEDIUM | 4.3 | 0.3% | Oct 10, 2024 | The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing c... |
| CVE-2024-9457 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up... |
| CVE-2024-9377 | MEDIUM | 6.1 | 0.4% | Oct 10, 2024 | The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Script... |
| CVE-2024-9205 | MEDIUM | 6.1 | 0.3% | Oct 10, 2024 | The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t... |
| CVE-2024-9072 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File... |
| CVE-2024-9066 | MEDIUM | 5.4 | 0.2% | Oct 10, 2024 | The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ... |
| CVE-2024-9065 | MEDIUM | 5.3 | 0.4% | Oct 10, 2024 | The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-9064 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v... |
| CVE-2024-9057 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2024-8987 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
| CVE-2024-8729 | MEDIUM | 6.1 | 0.3% | Oct 10, 2024 | The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add... |
| CVE-2024-8513 | MEDIUM | 5.3 | 0.4% | Oct 10, 2024 | The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable... |
| CVE-2024-7048 | MEDIUM | 5.4 | 0.4% | Oct 10, 2024 | In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/... |
| CVE-2024-48942 | MEDIUM | 5.9 | 0.5% | Oct 10, 2024 | The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to eas... |
| CVE-2024-48941 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to byp... |
| CVE-2024-8264 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent... |
| CVE-2024-48933 | MEDIUM | 6.1 | 0.3% | Oct 9, 2024 | A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary we... |
| CVE-2024-7041 | MEDIUM | 6.5 | 0.4% | Oct 9, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerabili... |
| CVE-2024-38818 | MEDIUM | 6.7 | 0.3% | Oct 9, 2024 | VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vuln... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now