2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9320 | MEDIUM | 5.4 | 0.4% | Sep 29, 2024 | A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerabil... |
| CVE-2024-9300 | MEDIUM | 6.1 | 0.6% | Sep 28, 2024 | A vulnerability classified as problematic was found in SourceCodester Online Railway Reservation System 1.0. This vulner... |
| CVE-2024-9299 | MEDIUM | 5.4 | 0.4% | Sep 28, 2024 | A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This a... |
| CVE-2024-9298 | MEDIUM | 4.3 | 0.5% | Sep 28, 2024 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been rated as problematic. Aff... |
| CVE-2024-8189 | MEDIUM | 4.8 | 0.4% | Sep 28, 2024 | The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmt_menu_... |
| CVE-2024-9297 | MEDIUM | 6.3 | 0.4% | Sep 28, 2024 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been declared as critical. Aff... |
| CVE-2024-8712 | MEDIUM | 6.1 | 0.4% | Sep 28, 2024 | The GTM Server Side plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg... |
| CVE-2024-23961 | MEDIUM | 6.8 | 1.0% | Sep 28, 2024 | Alpine Halo9 UPDM_wemCmdUpdFSpeDecomp Command Injection Remote Code Execution Vulnerability. This vulnerability allows p... |
| CVE-2024-23960 | MEDIUM | 4.6 | 0.3% | Sep 28, 2024 | Alpine Halo9 Improper Verification of Cryptographic Signature Vulnerability. This vulnerability allows physically presen... |
| CVE-2024-23924 | MEDIUM | 6.8 | 1.0% | Sep 28, 2024 | Alpine Halo9 UPDM_wemCmdCreatSHA256Hash Command Injection Remote Code Execution Vulnerability. This vulnerability allows... |
| CVE-2024-8715 | MEDIUM | 6.1 | 0.4% | Sep 28, 2024 | The Simple LDAP Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a... |
| CVE-2024-9189 | MEDIUM | 5.3 | 0.5% | Sep 28, 2024 | The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a m... |
| CVE-2024-9023 | MEDIUM | 5.4 | 0.4% | Sep 28, 2024 | The WP-WebAuthn plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wwa_login_form shortc... |
| CVE-2024-8788 | MEDIUM | 6.1 | 0.4% | Sep 28, 2024 | The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us... |
| CVE-2024-8547 | MEDIUM | 5.4 | 0.4% | Sep 28, 2024 | The Simple Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [popup] short... |
| CVE-2024-9294 | MEDIUM | 6.3 | 0.3% | Sep 27, 2024 | A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff922722... |
| CVE-2024-38796 | MEDIUM | 5.9 | 0.4% | Sep 27, 2024 | EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an over... |
| CVE-2024-9291 | MEDIUM | 5.4 | 0.4% | Sep 27, 2024 | A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75... |
| CVE-2024-47186 | MEDIUM | 6.1 | 0.4% | Sep 27, 2024 | Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2... |
| CVE-2024-46453 | MEDIUM | 6.1 | 0.3% | Sep 27, 2024 | A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execut... |
| CVE-2024-6436 | MEDIUM | 6.5 | 0.6% | Sep 27, 2024 | An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user... |
| CVE-2024-9160 | MEDIUM | 5.4 | 0.2% | Sep 27, 2024 | In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered. |
| CVE-2024-46257 | MEDIUM | 6.3 | 1.3% | Sep 27, 2024 | A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacke... |
| CVE-2024-38308 | MEDIUM | 6.1 | 0.3% | Sep 27, 2024 | Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the ... |
| CVE-2024-37187 | MEDIUM | 5.7 | 0.4% | Sep 27, 2024 | Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now