2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25691 | MEDIUM | 6.1 | 0.3% | Oct 4, 2024 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and below which may allow a remote, unaut... |
| CVE-2024-46409 | MEDIUM | 5.4 | 0.3% | Oct 4, 2024 | A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts o... |
| CVE-2024-47765 | MEDIUM | 6.1 | 0.4% | Oct 4, 2024 | Minecraft MOTD Parser is a PHP library to parse minecraft server motd. The HtmlGenerator class is subject to potential c... |
| CVE-2024-9410 | MEDIUM | 5.3 | 0.3% | Oct 4, 2024 | Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping ... |
| CVE-2024-9484 | MEDIUM | 5.5 | 0.1% | Oct 4, 2024 | An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on Ma... |
| CVE-2024-9483 | MEDIUM | 5.5 | 0.1% | Oct 4, 2024 | A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 2... |
| CVE-2024-9482 | MEDIUM | 5.5 | 0.1% | Oct 4, 2024 | An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS ... |
| CVE-2024-9481 | MEDIUM | 5.5 | 0.1% | Oct 4, 2024 | An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS ... |
| CVE-2024-8499 | MEDIUM | 6.1 | 0.4% | Oct 4, 2024 | The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site ... |
| CVE-2024-47657 | MEDIUM | 6.5 | 0.4% | Oct 4, 2024 | This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An aut... |
| CVE-2024-47653 | MEDIUM | 6.5 | 0.3% | Oct 4, 2024 | This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requ... |
| CVE-2024-47651 | MEDIUM | 6.5 | 0.4% | Oct 4, 2024 | This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint... |
| CVE-2024-9271 | MEDIUM | 5.4 | 0.3% | Oct 4, 2024 | The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, ... |
| CVE-2024-9071 | MEDIUM | 5.4 | 0.3% | Oct 4, 2024 | The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2024-9435 | MEDIUM | 6.1 | 0.4% | Oct 4, 2024 | The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via U... |
| CVE-2024-9306 | MEDIUM | 4.8 | 0.3% | Oct 4, 2024 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers... |
| CVE-2024-6444 | MEDIUM | 6.5 | 0.3% | Oct 4, 2024 | No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.... |
| CVE-2024-9242 | MEDIUM | 5.4 | 0.3% | Oct 4, 2024 | The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'me... |
| CVE-2024-8804 | MEDIUM | 5.4 | 0.2% | Oct 4, 2024 | The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functiona... |
| CVE-2024-6443 | MEDIUM | 6.5 | 0.6% | Oct 4, 2024 | In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is e... |
| CVE-2024-6442 | MEDIUM | 6.5 | 0.3% | Oct 4, 2024 | In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow. |
| CVE-2024-47855 | MEDIUM | 5.3 | 15.4% | Oct 4, 2024 | util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string. |
| CVE-2024-47854 | MEDIUM | 6.1 | 0.7% | Oct 4, 2024 | An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitra... |
| CVE-2024-9445 | MEDIUM | 5.4 | 0.3% | Oct 4, 2024 | The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medi... |
| CVE-2024-9421 | MEDIUM | 5.4 | 0.3% | Oct 4, 2024 | The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now