2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42020 | MEDIUM | 5.4 | 0.4% | Sep 7, 2024 | A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection. |
| CVE-2024-8558 | MEDIUM | 4.3 | 0.6% | Sep 7, 2024 | A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerab... |
| CVE-2024-8555 | MEDIUM | 6.1 | 0.6% | Sep 7, 2024 | A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic... |
| CVE-2024-8554 | MEDIUM | 5.4 | 0.5% | Sep 7, 2024 | A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This is... |
| CVE-2024-40680 | MEDIUM | 5.5 | 0.2% | Sep 7, 2024 | IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation cau... |
| CVE-2024-7620 | MEDIUM | 6.6 | 0.7% | Sep 7, 2024 | The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2024-7112 | MEDIUM | 6.5 | 0.5% | Sep 7, 2024 | The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘s... |
| CVE-2024-6010 | MEDIUM | 5.3 | 0.4% | Sep 7, 2024 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and incl... |
| CVE-2024-1596 | MEDIUM | 6.1 | 0.4% | Sep 7, 2024 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e... |
| CVE-2024-8538 | MEDIUM | 4.3 | 0.6% | Sep 7, 2024 | The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in a... |
| CVE-2024-6849 | MEDIUM | 5.4 | 0.3% | Sep 7, 2024 | The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-8521 | MEDIUM | 6.1 | 0.5% | Sep 7, 2024 | A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index o... |
| CVE-2024-34155 | MEDIUM | 4.3 | 0.8% | Sep 6, 2024 | Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stac... |
| CVE-2024-8394 | MEDIUM | 6.5 | 0.3% | Sep 6, 2024 | When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a p... |
| CVE-2024-38640 | MEDIUM | 5.4 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability... |
| CVE-2024-32762 | MEDIUM | 6.1 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability cou... |
| CVE-2024-27126 | MEDIUM | 5.4 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability ... |
| CVE-2024-27125 | MEDIUM | 4.8 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could a... |
| CVE-2024-27122 | MEDIUM | 5.4 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability ... |
| CVE-2024-21906 | MEDIUM | 4.7 | 0.8% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2024-21904 | MEDIUM | 6.5 | 0.3% | Sep 6, 2024 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul... |
| CVE-2024-21903 | MEDIUM | 4.7 | 0.8% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2024-21897 | MEDIUM | 5.4 | 0.3% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi... |
| CVE-2024-25584 | MEDIUM | 5.3 | 0.2% | Sep 6, 2024 | Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This... |
| CVE-2024-7622 | MEDIUM | 4.3 | 0.4% | Sep 6, 2024 | The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing cap... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now