2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45815 | MEDIUM | 6.5 | 0.5% | Sep 17, 2024 | Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstag... |
| CVE-2024-8951 | MEDIUM | 6.1 | 0.4% | Sep 17, 2024 | A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vu... |
| CVE-2024-45812 | MEDIUM | 6.4 | 0.6% | Sep 17, 2024 | Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobb... |
| CVE-2024-45811 | MEDIUM | 4.8 | 1.0% | Sep 17, 2024 | Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be retu... |
| CVE-2024-45606 | MEDIUM | 4.3 | 0.4% | Sep 17, 2024 | Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rul... |
| CVE-2024-45605 | MEDIUM | 4.3 | 0.4% | Sep 17, 2024 | Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user is... |
| CVE-2024-45604 | MEDIUM | 4.3 | 0.4% | Sep 17, 2024 | Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the docume... |
| CVE-2024-8660 | MEDIUM | 4.8 | 0.3% | Sep 17, 2024 | Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. S... |
| CVE-2024-45803 | MEDIUM | 6.1 | 0.4% | Sep 17, 2024 | Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cr... |
| CVE-2024-45612 | MEDIUM | 5.3 | 0.3% | Sep 17, 2024 | Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, whic... |
| CVE-2024-45537 | MEDIUM | 6.5 | 0.6% | Sep 17, 2024 | Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionali... |
| CVE-2024-45384 | MEDIUM | 5.3 | 0.8% | Sep 17, 2024 | Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j ... |
| CVE-2024-8796 | MEDIUM | 5.3 | 0.6% | Sep 17, 2024 | Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120... |
| CVE-2024-38380 | MEDIUM | 5.4 | 0.4% | Sep 17, 2024 | This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser... |
| CVE-2024-8939 | MEDIUM | 6.2 | 0.2% | Sep 17, 2024 | A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vll... |
| CVE-2024-38860 | MEDIUM | 6.1 | 0.3% | Sep 17, 2024 | Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious li... |
| CVE-2024-8897 | MEDIUM | 6.1 | 6.9% | Sep 17, 2024 | Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a t... |
| CVE-2024-8761 | MEDIUM | 6.1 | 0.4% | Sep 17, 2024 | The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. Thi... |
| CVE-2024-8490 | MEDIUM | 6.5 | 0.3% | Sep 17, 2024 | The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-8093 | MEDIUM | 6.5 | 0.2% | Sep 17, 2024 | The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2024-8092 | MEDIUM | 5.4 | 0.2% | Sep 17, 2024 | The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisa... |
| CVE-2024-8091 | MEDIUM | 6.5 | 0.2% | Sep 17, 2024 | The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, whi... |
| CVE-2024-8052 | MEDIUM | 6.1 | 0.2% | Sep 17, 2024 | The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as ... |
| CVE-2024-8051 | MEDIUM | 5.4 | 0.2% | Sep 17, 2024 | The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisati... |
| CVE-2024-8047 | MEDIUM | 6.5 | 0.2% | Sep 17, 2024 | The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now