2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9384 | MEDIUM | 6.1 | 0.4% | Oct 4, 2024 | The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site... |
| CVE-2024-9375 | MEDIUM | 6.1 | 0.3% | Oct 4, 2024 | The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to... |
| CVE-2024-9372 | MEDIUM | 5.4 | 0.2% | Oct 4, 2024 | The WP Blocks Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions... |
| CVE-2024-9368 | MEDIUM | 5.4 | 0.2% | Oct 4, 2024 | The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ... |
| CVE-2024-9353 | MEDIUM | 6.1 | 0.4% | Oct 4, 2024 | The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg... |
| CVE-2024-9349 | MEDIUM | 6.1 | 0.4% | Oct 4, 2024 | The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Sc... |
| CVE-2024-9345 | MEDIUM | 6.1 | 0.4% | Oct 4, 2024 | The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du... |
| CVE-2024-9237 | MEDIUM | 6.1 | 0.4% | Oct 4, 2024 | The Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate plugin for WordPress is vulnerable t... |
| CVE-2024-9204 | MEDIUM | 6.1 | 0.4% | Oct 4, 2024 | The Smart Custom 404 Error Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUE... |
| CVE-2024-8802 | MEDIUM | 6.1 | 0.4% | Oct 4, 2024 | The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho... |
| CVE-2024-8520 | MEDIUM | 4.3 | 0.3% | Oct 4, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2024-8519 | MEDIUM | 5.4 | 0.4% | Oct 4, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2024-44207 | MEDIUM | 4.3 | 9.2% | Oct 4, 2024 | This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Me... |
| CVE-2024-44204 | MEDIUM | 5.5 | 4.9% | Oct 4, 2024 | A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's save... |
| CVE-2024-9266 | MEDIUM | 4.7 | 0.4% | Oct 3, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the ... |
| CVE-2024-41591 | MEDIUM | 6.1 | 0.2% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS. |
| CVE-2024-41587 | MEDIUM | 5.4 | 0.2% | Oct 3, 2024 | Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor31... |
| CVE-2024-41585 | MEDIUM | 6.8 | 0.8% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker ... |
| CVE-2024-41584 | MEDIUM | 4.7 | 0.3% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing vali... |
| CVE-2024-41583 | MEDIUM | 4.7 | 0.3% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due... |
| CVE-2024-47762 | MEDIUM | 5.8 | 0.4% | Oct 3, 2024 | Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment v... |
| CVE-2024-34535 | MEDIUM | 5.9 | 0.4% | Oct 3, 2024 | In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header. |
| CVE-2024-8508 | MEDIUM | 5.3 | 0.8% | Oct 3, 2024 | NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRs... |
| CVE-2024-45872 | MEDIUM | 6.3 | 0.4% | Oct 3, 2024 | Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient... |
| CVE-2024-45871 | MEDIUM | 6.3 | 0.4% | Oct 3, 2024 | Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS). |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now