2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44821 | MEDIUM | 5.3 | 0.4% | Sep 4, 2024 | ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does ... |
| CVE-2024-44818 | MEDIUM | 5.4 | 0.4% | Sep 4, 2024 | Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information v... |
| CVE-2024-8411 | MEDIUM | 4.3 | 0.5% | Sep 4, 2024 | A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_int... |
| CVE-2024-7077 | MEDIUM | 6.1 | 0.2% | Sep 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics... |
| CVE-2024-44820 | MEDIUM | 6.1 | 0.4% | Sep 4, 2024 | A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at... |
| CVE-2024-44819 | MEDIUM | 6.1 | 0.4% | Sep 4, 2024 | Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information v... |
| CVE-2024-8407 | MEDIUM | 5.4 | 0.4% | Sep 4, 2024 | A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as p... |
| CVE-2024-44383 | MEDIUM | 6.8 | 0.5% | Sep 4, 2024 | WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm. |
| CVE-2024-8413 | MEDIUM | 6.1 | 0.2% | Sep 4, 2024 | Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://g... |
| CVE-2024-8318 | MEDIUM | 5.4 | 0.3% | Sep 4, 2024 | The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks... |
| CVE-2024-8123 | MEDIUM | 5.4 | 0.3% | Sep 4, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference ... |
| CVE-2024-8121 | MEDIUM | 4.3 | 0.3% | Sep 4, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user... |
| CVE-2024-8119 | MEDIUM | 6.1 | 0.4% | Sep 4, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi... |
| CVE-2024-8117 | MEDIUM | 6.1 | 0.4% | Sep 4, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi... |
| CVE-2024-8106 | MEDIUM | 6.5 | 0.5% | Sep 4, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in... |
| CVE-2024-8104 | MEDIUM | 6.5 | 1.0% | Sep 4, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versio... |
| CVE-2024-8325 | MEDIUM | 5.4 | 0.2% | Sep 4, 2024 | The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Count... |
| CVE-2024-7786 | MEDIUM | 5.3 | 1.6% | Sep 4, 2024 | The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthentica... |
| CVE-2024-6889 | MEDIUM | 4.8 | 0.4% | Sep 4, 2024 | The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some o... |
| CVE-2024-6888 | MEDIUM | 4.8 | 0.4% | Sep 4, 2024 | The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some o... |
| CVE-2024-6722 | MEDIUM | 4.8 | 0.3% | Sep 4, 2024 | The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and e... |
| CVE-2024-6020 | MEDIUM | 6.1 | 0.4% | Sep 4, 2024 | The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_... |
| CVE-2024-34661 | MEDIUM | 4.3 | 0.3% | Sep 4, 2024 | Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to ... |
| CVE-2024-34659 | MEDIUM | 5.3 | 0.5% | Sep 4, 2024 | Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victi... |
| CVE-2024-34655 | MEDIUM | 5.5 | 0.1% | Sep 4, 2024 | Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now