2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8291 | MEDIUM | 4.8 | 0.5% | Sep 25, 2024 | Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A ... |
| CVE-2024-8267 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable ... |
| CVE-2024-8103 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in ... |
| CVE-2024-8067 | MEDIUM | 5.8 | 0.2% | Sep 25, 2024 | In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument inject... |
| CVE-2024-7398 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addit... |
| CVE-2024-47048 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release no... |
| CVE-2024-46934 | MEDIUM | 6.1 | 0.3% | Sep 25, 2024 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XS... |
| CVE-2024-41725 | MEDIUM | 6.1 | 0.4% | Sep 25, 2024 | ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may ... |
| CVE-2024-38324 | MEDIUM | 6.5 | 0.3% | Sep 25, 2024 | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registrati... |
| CVE-2024-8794 | MEDIUM | 5.3 | 0.4% | Sep 24, 2024 | The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and includi... |
| CVE-2024-8628 | MEDIUM | 5.4 | 0.3% | Sep 24, 2024 | The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable ... |
| CVE-2024-8738 | MEDIUM | 6.1 | 0.4% | Sep 24, 2024 | The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu... |
| CVE-2024-8716 | MEDIUM | 6.1 | 0.4% | Sep 24, 2024 | The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ... |
| CVE-2024-8662 | MEDIUM | 6.1 | 0.4% | Sep 24, 2024 | The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ... |
| CVE-2024-8657 | MEDIUM | 5.4 | 0.4% | Sep 24, 2024 | The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortc... |
| CVE-2024-8544 | MEDIUM | 6.1 | 0.5% | Sep 24, 2024 | The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the... |
| CVE-2024-8432 | MEDIUM | 4.3 | 0.4% | Sep 24, 2024 | The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2024-38269 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel ... |
| CVE-2024-38268 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG882... |
| CVE-2024-38267 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG88... |
| CVE-2024-38266 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG... |
| CVE-2024-7022 | MEDIUM | 4.3 | 0.3% | Sep 23, 2024 | Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memor... |
| CVE-2024-7020 | MEDIUM | 4.3 | 0.3% | Sep 23, 2024 | Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI... |
| CVE-2024-7019 | MEDIUM | 4.3 | 0.3% | Sep 23, 2024 | Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a use... |
| CVE-2024-8770 | MEDIUM | 6.1 | 0.3% | Sep 23, 2024 | A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now