2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20414 | MEDIUM | 6.5 | 0.3% | Sep 25, 2024 | A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re... |
| CVE-2024-7421 | MEDIUM | 5.5 | 0.2% | Sep 25, 2024 | An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers ... |
| CVE-2024-46600 | MEDIUM | 4.7 | 0.2% | Sep 25, 2024 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.p... |
| CVE-2024-46485 | MEDIUM | 6.3 | 0.2% | Sep 25, 2024 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate |
| CVE-2024-43990 | MEDIUM | 5.3 | 0.4% | Sep 25, 2024 | Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affe... |
| CVE-2024-43237 | MEDIUM | 5.3 | 0.3% | Sep 25, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Steve Burge WordPress Tag Cloud Plugin – Tag... |
| CVE-2024-30128 | MEDIUM | 6.5 | 0.4% | Sep 25, 2024 | HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask thei... |
| CVE-2024-6512 | MEDIUM | 6.5 | 0.3% | Sep 25, 2024 | Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows aut... |
| CVE-2024-45613 | MEDIUM | 6.1 | 0.5% | Sep 25, 2024 | CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Script... |
| CVE-2024-8546 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Vide... |
| CVE-2024-8858 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_set... |
| CVE-2024-9169 | MEDIUM | 4.8 | 0.3% | Sep 25, 2024 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all v... |
| CVE-2024-47303 | MEDIUM | 5.4 | 0.2% | Sep 25, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh ... |
| CVE-2024-40761 | MEDIUM | 5.3 | 0.7% | Sep 25, 2024 | Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using ... |
| CVE-2024-23454 | MEDIUM | 6.2 | 0.4% | Sep 25, 2024 | Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be pres... |
| CVE-2024-8910 | MEDIUM | 4.3 | 0.3% | Sep 25, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ... |
| CVE-2024-8678 | MEDIUM | 5.3 | 0.3% | Sep 25, 2024 | The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-3866 | MEDIUM | 6.1 | 0.3% | Sep 25, 2024 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Re... |
| CVE-2024-8658 | MEDIUM | 5.3 | 0.3% | Sep 25, 2024 | The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo... |
| CVE-2024-7892 | MEDIUM | 4.3 | 0.2% | Sep 25, 2024 | The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2024-7878 | MEDIUM | 4.8 | 0.4% | Sep 25, 2024 | The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-6845 | MEDIUM | 5.3 | 1.1% | Sep 25, 2024 | The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, a... |
| CVE-2024-8668 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2024-8516 | MEDIUM | 4.3 | 0.4% | Sep 25, 2024 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an... |
| CVE-2024-8515 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now