2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43280 | MEDIUM | 6.1 | 0.2% | Aug 19, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issu... |
| CVE-2024-43272 | MEDIUM | 5.3 | 0.4% | Aug 19, 2024 | Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properl... |
| CVE-2024-43250 | MEDIUM | 6.5 | 0.3% | Aug 19, 2024 | Incorrect Authorization vulnerability in Bit Apps Bit Form Pro bitformpro allows Accessing Functionality Not Properly Co... |
| CVE-2024-43400 | MEDIUM | 5.4 | 0.5% | Aug 19, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible ... |
| CVE-2024-43236 | MEDIUM | 4.7 | 0.3% | Aug 19, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal Buy Now Button.This issu... |
| CVE-2024-32928 | MEDIUM | 5.9 | 0.2% | Aug 19, 2024 | The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which ena... |
| CVE-2024-25582 | MEDIUM | 5.4 | 0.4% | Aug 19, 2024 | Module savepoints could be abused to inject references to malicious code delivered through the same domain. Attackers co... |
| CVE-2024-6843 | MEDIUM | 6.1 | 0.4% | Aug 19, 2024 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unaut... |
| CVE-2024-7916 | MEDIUM | 5.4 | 0.4% | Aug 18, 2024 | A vulnerability classified as problematic was found in nafisulbari/itsourcecode Insurance Management System 1.0. Affecte... |
| CVE-2024-7914 | MEDIUM | 5.4 | 0.4% | Aug 18, 2024 | A vulnerability classified as problematic has been found in SourceCodester Yoga Class Registration System 1.0. Affected ... |
| CVE-2024-7912 | MEDIUM | 5.3 | 0.8% | Aug 18, 2024 | A vulnerability was found in CodeAstro Online Railway Reservation System 1.0. It has been declared as problematic. This ... |
| CVE-2024-43350 | MEDIUM | 5.3 | 0.3% | Aug 18, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoic... |
| CVE-2024-43294 | MEDIUM | 6.5 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BoldThemes ... |
| CVE-2024-43292 | MEDIUM | 5.4 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EnvoThemes ... |
| CVE-2024-43291 | MEDIUM | 4.8 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in voidCoders ... |
| CVE-2024-43284 | MEDIUM | 6.5 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Travel W... |
| CVE-2024-43278 | MEDIUM | 6.5 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Phi Phan Me... |
| CVE-2024-43267 | MEDIUM | 6.5 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Qamar Sheer... |
| CVE-2024-43263 | MEDIUM | 6.5 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Visual Comp... |
| CVE-2024-43262 | MEDIUM | 6.5 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in webriti Bus... |
| CVE-2024-35686 | MEDIUM | 5.3 | 0.5% | Aug 18, 2024 | Missing Authorization vulnerability in Automattic Sensei LMS, Automattic Sensei Pro (WC Paid Courses).This issue affects... |
| CVE-2024-43304 | MEDIUM | 6.1 | 0.3% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cool Plugin... |
| CVE-2024-43321 | MEDIUM | 6.5 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins... |
| CVE-2024-43320 | MEDIUM | 6.5 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Li... |
| CVE-2024-43318 | MEDIUM | 5.4 | 0.2% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf e2pdf e2pdf.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now