2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9161 | MEDIUM | 6.5 | 2.0% | Oct 5, 2024 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modificatio... |
| CVE-2024-9146 | MEDIUM | 4.9 | 0.6% | Oct 5, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in jamesdlow CSS JS Files c... |
| CVE-2024-9417 | MEDIUM | 6.1 | 0.3% | Oct 5, 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigur... |
| CVE-2024-8486 | MEDIUM | 5.4 | 0.4% | Oct 5, 2024 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-8743 | MEDIUM | 6.8 | 0.8% | Oct 5, 2024 | The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulner... |
| CVE-2024-9528 | MEDIUM | 4.8 | 0.4% | Oct 5, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-9455 | MEDIUM | 6.4 | 0.3% | Oct 5, 2024 | The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upload... |
| CVE-2024-9385 | MEDIUM | 6.1 | 0.4% | Oct 5, 2024 | The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg... |
| CVE-2024-47847 | MEDIUM | 6.1 | 0.4% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2024-47840 | MEDIUM | 4.8 | 0.3% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2024-47848 | MEDIUM | 6.9 | 0.5% | Oct 5, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTri... |
| CVE-2024-47913 | MEDIUM | 5.3 | 0.4% | Oct 4, 2024 | An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1... |
| CVE-2024-7801 | MEDIUM | 6.5 | 0.8% | Oct 4, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProv... |
| CVE-2024-47764 | MEDIUM | 6.9 | 0.7% | Oct 4, 2024 | cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields ... |
| CVE-2024-43687 | MEDIUM | 6.1 | 0.8% | Oct 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip T... |
| CVE-2024-43686 | MEDIUM | 6.1 | 11.2% | Oct 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip T... |
| CVE-2024-43683 | MEDIUM | 6.1 | 0.2% | Oct 4, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP... |
| CVE-2024-46077 | MEDIUM | 5.4 | 0.3% | Oct 4, 2024 | itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted p... |
| CVE-2024-8149 | MEDIUM | 4.6 | 0.4% | Oct 4, 2024 | There is a reflected Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.1 and 11.2 that may ... |
| CVE-2024-8148 | MEDIUM | 6.1 | 0.3% | Oct 4, 2024 | There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthe... |
| CVE-2024-47211 | MEDIUM | 5.3 | 0.7% | Oct 4, 2024 | In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26... |
| CVE-2024-44439 | MEDIUM | 5.9 | 0.2% | Oct 4, 2024 | An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things S... |
| CVE-2024-41516 | MEDIUM | 5.4 | 0.4% | Oct 4, 2024 | A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to i... |
| CVE-2024-41515 | MEDIUM | 5.4 | 0.4% | Oct 4, 2024 | A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote att... |
| CVE-2024-41514 | MEDIUM | 5.4 | 0.4% | Oct 4, 2024 | A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now