2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7689 | MEDIUM | 4.3 | 0.2% | Sep 9, 2024 | The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation ... |
| CVE-2024-7688 | MEDIUM | 6.5 | 0.2% | Sep 9, 2024 | The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make... |
| CVE-2024-7687 | MEDIUM | 4.3 | 0.2% | Sep 9, 2024 | The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well ... |
| CVE-2024-6910 | MEDIUM | 4.8 | 0.3% | Sep 9, 2024 | The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2024-5561 | MEDIUM | 4.8 | 0.4% | Sep 9, 2024 | The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-45625 | MEDIUM | 6.1 | 0.4% | Sep 9, 2024 | Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an... |
| CVE-2024-8586 | MEDIUM | 6.1 | 0.4% | Sep 9, 2024 | WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulner... |
| CVE-2024-8585 | MEDIUM | 6.5 | 0.7% | Sep 9, 2024 | Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowi... |
| CVE-2024-8583 | MEDIUM | 5.4 | 0.4% | Sep 8, 2024 | A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It ha... |
| CVE-2024-8582 | MEDIUM | 6.1 | 0.4% | Sep 8, 2024 | A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected ... |
| CVE-2024-42342 | MEDIUM | 4.3 | 0.3% | Sep 8, 2024 | Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| CVE-2024-42341 | MEDIUM | 6.1 | 0.2% | Sep 8, 2024 | Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') |
| CVE-2024-8572 | MEDIUM | 6.1 | 0.4% | Sep 8, 2024 | A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affect... |
| CVE-2024-8571 | MEDIUM | 5.3 | 0.4% | Sep 8, 2024 | A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as ... |
| CVE-2024-6925 | MEDIUM | 4.3 | 0.2% | Sep 8, 2024 | The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could ... |
| CVE-2024-6859 | MEDIUM | 5.4 | 0.2% | Sep 8, 2024 | The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes befor... |
| CVE-2024-6856 | MEDIUM | 4.3 | 0.2% | Sep 8, 2024 | The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which... |
| CVE-2024-6855 | MEDIUM | 4.3 | 0.2% | Sep 8, 2024 | The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could all... |
| CVE-2024-6853 | MEDIUM | 4.3 | 0.2% | Sep 8, 2024 | The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could ... |
| CVE-2024-6852 | MEDIUM | 4.3 | 0.2% | Sep 8, 2024 | The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which... |
| CVE-2024-8566 | MEDIUM | 6.1 | 0.4% | Sep 8, 2024 | A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects u... |
| CVE-2024-8563 | MEDIUM | 6.1 | 0.4% | Sep 7, 2024 | A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown... |
| CVE-2024-8562 | MEDIUM | 6.1 | 0.3% | Sep 7, 2024 | A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some u... |
| CVE-2024-42022 | MEDIUM | 5.3 | 0.3% | Sep 7, 2024 | An incorrect permission assignment vulnerability allows an attacker to modify product configuration files. |
| CVE-2024-42021 | MEDIUM | 6.5 | 0.3% | Sep 7, 2024 | An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now