2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45200 | MEDIUM | 6.3 | 1.4% | Sep 30, 2024 | In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to e... |
| CVE-2024-41999 | MEDIUM | 6.8 | 0.3% | Sep 30, 2024 | Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability... |
| CVE-2024-8449 | MEDIUM | 6.8 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allo... |
| CVE-2024-8536 | MEDIUM | 5.4 | 0.3% | Sep 30, 2024 | The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outp... |
| CVE-2024-8283 | MEDIUM | 4.8 | 0.4% | Sep 30, 2024 | The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow... |
| CVE-2024-8239 | MEDIUM | 5.4 | 0.3% | Sep 30, 2024 | The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like... |
| CVE-2024-3635 | MEDIUM | 4.8 | 0.3% | Sep 30, 2024 | The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow h... |
| CVE-2024-9323 | MEDIUM | 5.4 | 0.4% | Sep 29, 2024 | A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affect... |
| CVE-2024-9321 | MEDIUM | 5.3 | 0.6% | Sep 29, 2024 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue... |
| CVE-2024-9320 | MEDIUM | 5.4 | 0.4% | Sep 29, 2024 | A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerabil... |
| CVE-2024-9300 | MEDIUM | 6.1 | 0.6% | Sep 28, 2024 | A vulnerability classified as problematic was found in SourceCodester Online Railway Reservation System 1.0. This vulner... |
| CVE-2024-9299 | MEDIUM | 5.4 | 0.4% | Sep 28, 2024 | A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This a... |
| CVE-2024-9298 | MEDIUM | 4.3 | 0.5% | Sep 28, 2024 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been rated as problematic. Aff... |
| CVE-2024-8189 | MEDIUM | 4.8 | 0.4% | Sep 28, 2024 | The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmt_menu_... |
| CVE-2024-9297 | MEDIUM | 6.3 | 0.4% | Sep 28, 2024 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Aff... |
| CVE-2024-8712 | MEDIUM | 6.1 | 0.4% | Sep 28, 2024 | The GTM Server Side plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg... |
| CVE-2024-23961 | MEDIUM | 6.8 | 1.0% | Sep 28, 2024 | Alpine Halo9 UPDM_wemCmdUpdFSpeDecomp Command Injection Remote Code Execution Vulnerability. This vulnerability allows p... |
| CVE-2024-23960 | MEDIUM | 4.6 | 0.3% | Sep 28, 2024 | Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability allows physically presen... |
| CVE-2024-23924 | MEDIUM | 6.8 | 1.0% | Sep 28, 2024 | Alpine Halo9 UPDM_wemCmdCreatSHA256Hash Command Injection Remote Code Execution Vulnerability. This vulnerability allows... |
| CVE-2024-8715 | MEDIUM | 6.1 | 0.4% | Sep 28, 2024 | The Simple LDAP Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a... |
| CVE-2024-9189 | MEDIUM | 5.3 | 0.5% | Sep 28, 2024 | The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a m... |
| CVE-2024-9023 | MEDIUM | 5.4 | 0.4% | Sep 28, 2024 | The WP-WebAuthn plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wwa_login_form shortc... |
| CVE-2024-8788 | MEDIUM | 6.1 | 0.4% | Sep 28, 2024 | The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us... |
| CVE-2024-8547 | MEDIUM | 5.4 | 0.4% | Sep 28, 2024 | The Simple Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [popup] short... |
| CVE-2024-9294 | MEDIUM | 6.3 | 0.3% | Sep 27, 2024 | A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff922722... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now