2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46081 | MEDIUM | 5.4 | 0.3% | Oct 1, 2024 | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious p... |
| CVE-2024-46079 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter. |
| CVE-2024-31835 | MEDIUM | 4.8 | 0.9% | Oct 1, 2024 | Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-9398 | MEDIUM | 5.3 | 0.6% | Oct 1, 2024 | By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if... |
| CVE-2024-9397 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permiss... |
| CVE-2024-9395 | MEDIUM | 5.3 | 0.3% | Oct 1, 2024 | A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in th... |
| CVE-2024-9391 | MEDIUM | 6.5 | 0.3% | Oct 1, 2024 | A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full scr... |
| CVE-2024-47604 | MEDIUM | 6.1 | 0.7% | Oct 1, 2024 | NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handli... |
| CVE-2024-47071 | MEDIUM | 6.8 | 0.5% | Oct 1, 2024 | OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authent... |
| CVE-2024-45967 | MEDIUM | 4.7 | 0.4% | Oct 1, 2024 | Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget. |
| CVE-2024-45408 | MEDIUM | 6.5 | 0.4% | Oct 1, 2024 | eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that c... |
| CVE-2024-44610 | MEDIUM | 5.6 | 1.0% | Oct 1, 2024 | PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via sh... |
| CVE-2024-25658 | MEDIUM | 6.5 | 0.2% | Oct 1, 2024 | Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (w... |
| CVE-2024-44744 | MEDIUM | 5.7 | 0.3% | Oct 1, 2024 | An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted bina... |
| CVE-2024-9405 | MEDIUM | 5.3 | 0.4% | Oct 1, 2024 | An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting v... |
| CVE-2024-9118 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve... |
| CVE-2024-9060 | MEDIUM | 6.4 | 0.4% | Oct 1, 2024 | The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versio... |
| CVE-2024-9241 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query... |
| CVE-2024-9228 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o... |
| CVE-2024-9224 | MEDIUM | 6.5 | 1.4% | Oct 1, 2024 | The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1... |
| CVE-2024-9220 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_... |
| CVE-2024-9209 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query... |
| CVE-2024-8799 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ... |
| CVE-2024-8793 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress... |
| CVE-2024-8786 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now