2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45612 | MEDIUM | 5.3 | 0.3% | Sep 17, 2024 | Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, whic... |
| CVE-2024-45537 | MEDIUM | 6.5 | 0.6% | Sep 17, 2024 | Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionali... |
| CVE-2024-45384 | MEDIUM | 5.3 | 0.8% | Sep 17, 2024 | Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j ... |
| CVE-2024-8796 | MEDIUM | 5.3 | 0.6% | Sep 17, 2024 | Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120... |
| CVE-2024-38380 | MEDIUM | 5.4 | 0.4% | Sep 17, 2024 | This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser... |
| CVE-2024-8939 | MEDIUM | 6.2 | 0.2% | Sep 17, 2024 | A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vll... |
| CVE-2024-38860 | MEDIUM | 6.1 | 0.3% | Sep 17, 2024 | Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious li... |
| CVE-2024-8897 | MEDIUM | 6.1 | 6.9% | Sep 17, 2024 | Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a t... |
| CVE-2024-8761 | MEDIUM | 6.1 | 0.4% | Sep 17, 2024 | The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. Thi... |
| CVE-2024-8490 | MEDIUM | 6.5 | 0.3% | Sep 17, 2024 | The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-8093 | MEDIUM | 6.5 | 0.2% | Sep 17, 2024 | The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2024-8092 | MEDIUM | 5.4 | 0.2% | Sep 17, 2024 | The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisa... |
| CVE-2024-8091 | MEDIUM | 6.5 | 0.2% | Sep 17, 2024 | The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, whi... |
| CVE-2024-8052 | MEDIUM | 6.1 | 0.2% | Sep 17, 2024 | The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as ... |
| CVE-2024-8051 | MEDIUM | 5.4 | 0.2% | Sep 17, 2024 | The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisati... |
| CVE-2024-8047 | MEDIUM | 6.5 | 0.2% | Sep 17, 2024 | The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which... |
| CVE-2024-8044 | MEDIUM | 6.5 | 0.2% | Sep 17, 2024 | The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which... |
| CVE-2024-8043 | MEDIUM | 5.4 | 0.2% | Sep 17, 2024 | The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisati... |
| CVE-2024-5170 | MEDIUM | 4.8 | 0.3% | Sep 17, 2024 | The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which c... |
| CVE-2024-44202 | MEDIUM | 5.3 | 0.5% | Sep 17, 2024 | An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadO... |
| CVE-2024-44198 | MEDIUM | 5.5 | 0.2% | Sep 17, 2024 | An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS ... |
| CVE-2024-44191 | MEDIUM | 5.5 | 0.3% | Sep 17, 2024 | This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, i... |
| CVE-2024-44190 | MEDIUM | 5.5 | 0.2% | Sep 17, 2024 | A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7... |
| CVE-2024-44188 | MEDIUM | 5.5 | 0.2% | Sep 17, 2024 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be a... |
| CVE-2024-44187 | MEDIUM | 6.5 | 0.6% | Sep 17, 2024 | A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now