2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47161 | MEDIUM | 6.5 | 0.3% | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API |
| CVE-2024-45231 | MEDIUM | 5.3 | 0.8% | Oct 8, 2024 | An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, wh... |
| CVE-2024-33506 | MEDIUM | 4.3 | 0.4% | Oct 8, 2024 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7... |
| CVE-2024-8482 | MEDIUM | 6.4 | 0.4% | Oct 8, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’... |
| CVE-2024-8431 | MEDIUM | 4.3 | 0.4% | Oct 8, 2024 | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data... |
| CVE-2024-9207 | MEDIUM | 6.1 | 0.4% | Oct 8, 2024 | The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_... |
| CVE-2024-8488 | MEDIUM | 4.8 | 0.3% | Oct 8, 2024 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up ... |
| CVE-2024-8629 | MEDIUM | 6.1 | 0.4% | Oct 8, 2024 | The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Script... |
| CVE-2024-8433 | MEDIUM | 6.4 | 0.3% | Oct 8, 2024 | The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2024-47565 | MEDIUM | 4.3 | 0.4% | Oct 8, 2024 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not... |
| CVE-2024-47563 | MEDIUM | 5.3 | 0.5% | Oct 8, 2024 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not... |
| CVE-2024-46887 | MEDIUM | 6.9 | 0.5% | Oct 8, 2024 | The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' e... |
| CVE-2024-46886 | MEDIUM | 5.1 | 0.4% | Oct 8, 2024 | The web server of affected devices does not properly validate input that is used for a user redirection. This could allo... |
| CVE-2024-8964 | MEDIUM | 5.4 | 0.3% | Oct 8, 2024 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG Fi... |
| CVE-2024-47095 | MEDIUM | 5.1 | 0.5% | Oct 8, 2024 | Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run... |
| CVE-2024-34671 | MEDIUM | 5.5 | 0.2% | Oct 8, 2024 | Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows l... |
| CVE-2024-34670 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to... |
| CVE-2024-34663 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory... |
| CVE-2024-9292 | MEDIUM | 6.4 | 0.3% | Oct 8, 2024 | The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions... |
| CVE-2024-9021 | MEDIUM | 5.4 | 0.4% | Oct 8, 2024 | In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to i... |
| CVE-2024-8983 | MEDIUM | 4.8 | 0.4% | Oct 8, 2024 | Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-21533 | MEDIUM | 6.5 | 0.6% | Oct 8, 2024 | All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specif... |
| CVE-2024-8925 | MEDIUM | 5.3 | 0.9% | Oct 8, 2024 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data ... |
| CVE-2024-47594 | MEDIUM | 5.4 | 0.2% | Oct 8, 2024 | SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip... |
| CVE-2024-45382 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now