2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9115 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ... |
| CVE-2024-9025 | MEDIUM | 5.3 | 0.4% | Sep 26, 2024 | The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data d... |
| CVE-2024-8872 | MEDIUM | 6.1 | 0.4% | Sep 26, 2024 | The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a... |
| CVE-2024-47337 | MEDIUM | 4.3 | 0.3% | Sep 26, 2024 | Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: fr... |
| CVE-2024-47044 | MEDIUM | 5.3 | 0.4% | Sep 26, 2024 | Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to... |
| CVE-2024-8861 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2024-47145 | MEDIUM | 4.3 | 0.2% | Sep 26, 2024 | Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels... |
| CVE-2024-47003 | MEDIUM | 6.5 | 0.6% | Sep 26, 2024 | Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a str... |
| CVE-2024-45843 | MEDIUM | 5.4 | 0.2% | Sep 26, 2024 | Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denyli... |
| CVE-2024-42406 | MEDIUM | 5.4 | 0.2% | Sep 26, 2024 | Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize req... |
| CVE-2024-6517 | MEDIUM | 6.1 | 0.6% | Sep 26, 2024 | The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-45836 | MEDIUM | 6.1 | 0.2% | Sep 26, 2024 | Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logg... |
| CVE-2024-45372 | MEDIUM | 6.5 | 0.2% | Sep 26, 2024 | MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious pa... |
| CVE-2024-8803 | MEDIUM | 6.1 | 0.4% | Sep 26, 2024 | The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use ... |
| CVE-2024-8723 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The 012 Ps Multi Languages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via translated titles in al... |
| CVE-2024-8552 | MEDIUM | 4.3 | 0.4% | Sep 26, 2024 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2024-8405 | MEDIUM | 5.5 | 0.2% | Sep 26, 2024 | An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabl... |
| CVE-2024-46655 | MEDIUM | 6.1 | 0.3% | Sep 25, 2024 | A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in... |
| CVE-2024-46488 | MEDIUM | 5.5 | 0.4% | Sep 25, 2024 | sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability a... |
| CVE-2024-41445 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the Read... |
| CVE-2024-20508 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE So... |
| CVE-2024-20496 | MEDIUM | 6.1 | 0.2% | Sep 25, 2024 | A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacen... |
| CVE-2024-20475 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c... |
| CVE-2024-20465 | MEDIUM | 5.8 | 0.4% | Sep 25, 2024 | A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet ... |
| CVE-2024-20434 | MEDIUM | 4.3 | 0.2% | Sep 25, 2024 | A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now