2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7846 | MEDIUM | 5.4 | 0.3% | Sep 23, 2024 | YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied bloc... |
| CVE-2024-47227 | MEDIUM | 6.1 | 0.3% | Sep 23, 2024 | iRedAdmin before 2.6 allows XSS, e.g., via order_name. |
| CVE-2024-9092 | MEDIUM | 6.1 | 0.4% | Sep 23, 2024 | A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as proble... |
| CVE-2024-44048 | MEDIUM | 6.5 | 0.5% | Sep 23, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-43996 | MEDIUM | 6.5 | 0.6% | Sep 23, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit ... |
| CVE-2024-9089 | MEDIUM | 5.4 | 0.4% | Sep 23, 2024 | A vulnerability was found in SourceCodester Modern Loan Management System 1.0 and classified as problematic. This issue ... |
| CVE-2024-40703 | MEDIUM | 5.5 | 0.1% | Sep 22, 2024 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Re... |
| CVE-2024-9084 | MEDIUM | 5.4 | 0.4% | Sep 22, 2024 | A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u... |
| CVE-2024-9083 | MEDIUM | 4.8 | 0.4% | Sep 22, 2024 | A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects ... |
| CVE-2024-9077 | MEDIUM | 5.4 | 0.5% | Sep 22, 2024 | A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. A... |
| CVE-2024-47226 | MEDIUM | 5.4 | 0.3% | Sep 22, 2024 | A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of t... |
| CVE-2024-9075 | MEDIUM | 5.4 | 0.4% | Sep 21, 2024 | A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnera... |
| CVE-2024-9048 | MEDIUM | 6.1 | 0.4% | Sep 21, 2024 | A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerab... |
| CVE-2024-8680 | MEDIUM | 5.5 | 0.5% | Sep 21, 2024 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ... |
| CVE-2024-6787 | MEDIUM | 5.9 | 0.3% | Sep 21, 2024 | This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it ... |
| CVE-2024-6786 | MEDIUM | 6.5 | 0.5% | Sep 21, 2024 | The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling the... |
| CVE-2024-46647 | MEDIUM | 6.5 | 0.8% | Sep 20, 2024 | eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files. |
| CVE-2024-46646 | MEDIUM | 6.5 | 0.8% | Sep 20, 2024 | eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file. |
| CVE-2024-46644 | MEDIUM | 6.5 | 0.8% | Sep 20, 2024 | eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file. |
| CVE-2024-45793 | MEDIUM | 4.8 | 0.3% | Sep 20, 2024 | Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The foll... |
| CVE-2024-46654 | MEDIUM | 4.8 | 0.2% | Sep 20, 2024 | A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows at... |
| CVE-2024-45229 | MEDIUM | 6.6 | 0.5% | Sep 20, 2024 | The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen,... |
| CVE-2024-42346 | MEDIUM | 5.4 | 0.7% | Sep 20, 2024 | Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, ... |
| CVE-2024-42697 | MEDIUM | 6.1 | 0.3% | Sep 20, 2024 | Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to... |
| CVE-2024-9040 | MEDIUM | 5.5 | 0.2% | Sep 20, 2024 | A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now