2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47089 | MEDIUM | 6.5 | 0.2% | Sep 19, 2024 | This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API ... |
| CVE-2024-47087 | MEDIUM | 6.5 | 0.4% | Sep 19, 2024 | This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID ... |
| CVE-2024-47086 | MEDIUM | 6.5 | 0.5% | Sep 19, 2024 | This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism ... |
| CVE-2024-47085 | MEDIUM | 6.5 | 0.4% | Sep 19, 2024 | This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClic... |
| CVE-2024-8850 | MEDIUM | 6.1 | 0.4% | Sep 19, 2024 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' ... |
| CVE-2024-8364 | MEDIUM | 5.4 | 0.3% | Sep 19, 2024 | The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-pre... |
| CVE-2024-47059 | MEDIUM | 4.3 | 0.3% | Sep 18, 2024 | When logging in with the correct username and incorrect weak password, the user receives the notification, that their pa... |
| CVE-2024-47058 | MEDIUM | 4.8 | 0.2% | Sep 18, 2024 | With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be use... |
| CVE-2024-47050 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variabl... |
| CVE-2024-46372 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement manageme... |
| CVE-2024-43025 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and... |
| CVE-2024-43024 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to... |
| CVE-2024-46989 | MEDIUM | 5.3 | 0.3% | Sep 18, 2024 | spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for custom... |
| CVE-2024-46979 | MEDIUM | 5.3 | 0.5% | Sep 18, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t... |
| CVE-2024-46978 | MEDIUM | 6.5 | 0.5% | Sep 18, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible f... |
| CVE-2024-46959 | MEDIUM | 6.5 | 0.2% | Sep 18, 2024 | runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows ac... |
| CVE-2024-46990 | MEDIUM | 5 | 0.5% | Sep 18, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to loca... |
| CVE-2024-45813 | MEDIUM | 5.3 | 0.7% | Sep 18, 2024 | find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route ... |
| CVE-2024-45298 | MEDIUM | 4.3 | 0.4% | Sep 18, 2024 | Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the pass... |
| CVE-2024-6877 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Softwa... |
| CVE-2024-5959 | MEDIUM | 5.4 | 0.2% | Sep 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Softwa... |
| CVE-2024-8891 | MEDIUM | 5.3 | 0.3% | Sep 18, 2024 | An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users a... |
| CVE-2024-39081 | MEDIUM | 4.2 | 0.5% | Sep 18, 2024 | An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communicat... |
| CVE-2024-5682 | MEDIUM | 6.9 | 0.4% | Sep 18, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library ... |
| CVE-2024-43188 | MEDIUM | 4.9 | 0.3% | Sep 18, 2024 | IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthor... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now