2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8472 | MEDIUM | 6.1 | 0.3% | Sep 5, 2024 | Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of t... |
| CVE-2024-8471 | MEDIUM | 6.1 | 0.2% | Sep 5, 2024 | Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of t... |
| CVE-2024-8462 | MEDIUM | 6.3 | 0.5% | Sep 5, 2024 | A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of... |
| CVE-2024-8461 | MEDIUM | 5.3 | 1.9% | Sep 5, 2024 | A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part ... |
| CVE-2024-8460 | MEDIUM | 5.9 | 2.1% | Sep 5, 2024 | A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue i... |
| CVE-2024-7605 | MEDIUM | 4.3 | 0.4% | Sep 5, 2024 | The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2024-7381 | MEDIUM | 5.3 | 0.3% | Sep 5, 2024 | The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization a... |
| CVE-2024-7380 | MEDIUM | 4.3 | 0.3% | Sep 5, 2024 | The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability c... |
| CVE-2024-5956 | MEDIUM | 5.3 | 0.4% | Sep 5, 2024 | This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the ... |
| CVE-2024-6929 | MEDIUM | 5.4 | 0.3% | Sep 5, 2024 | The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ param... |
| CVE-2024-6894 | MEDIUM | 5.4 | 0.3% | Sep 5, 2024 | The RD Station plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5... |
| CVE-2024-6332 | MEDIUM | 6.5 | 0.4% | Sep 5, 2024 | The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unaut... |
| CVE-2024-8363 | MEDIUM | 5.4 | 0.4% | Sep 5, 2024 | The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shor... |
| CVE-2024-5309 | MEDIUM | 5.4 | 0.3% | Sep 5, 2024 | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modifi... |
| CVE-2024-45107 | MEDIUM | 5.5 | 0.3% | Sep 5, 2024 | Acrobat Reader versions 20.005.30636, 24.002.20964, 24.001.30123, 24.002.20991 and earlier are affected by a Use After F... |
| CVE-2024-6835 | MEDIUM | 5.3 | 0.5% | Sep 5, 2024 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up... |
| CVE-2024-6846 | MEDIUM | 5.3 | 1.3% | Sep 5, 2024 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an una... |
| CVE-2024-45429 | MEDIUM | 6.1 | 0.4% | Sep 4, 2024 | Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Field... |
| CVE-2024-2166 | MEDIUM | 6.1 | 0.3% | Sep 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email S... |
| CVE-2024-20506 | MEDIUM | 6.1 | 0.3% | Sep 4, 2024 | A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2... |
| CVE-2024-45399 | MEDIUM | 6.1 | 0.4% | Sep 4, 2024 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indi... |
| CVE-2024-45172 | MEDIUM | 6.8 | 0.4% | Sep 4, 2024 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanism... |
| CVE-2024-45008 | MEDIUM | 5.5 | 0.2% | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: Input: MT - limit max slots syzbot is reporting to... |
| CVE-2024-45007 | MEDIUM | 5.5 | 0.2% | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Don't destroy workqueue from work i... |
| CVE-2024-45006 | MEDIUM | 5.5 | 0.3% | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: xhci: Fix Panther point NULL pointer deref at full-... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now