2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32151 | MEDIUM | 5.9 | 1.3% | Nov 26, 2024 | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ... |
| CVE-2024-29978 | MEDIUM | 5.9 | 1.3% | Nov 26, 2024 | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ... |
| CVE-2024-29146 | MEDIUM | 5.9 | 0.9% | Nov 26, 2024 | User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ... |
| CVE-2024-28955 | MEDIUM | 5.9 | 1.3% | Nov 26, 2024 | Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the ... |
| CVE-2024-28038 | CRITICAL | 9 | 2.6% | Nov 26, 2024 | The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More ... |
| CVE-2024-11202 | MEDIUM | 6.1 | 0.6% | Nov 26, 2024 | Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in v... |
| CVE-2024-6749 | MEDIUM | 6.3 | 0.1% | Nov 26, 2024 | Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may exp... |
| CVE-2024-6476 | MEDIUM | 4.2 | 0.1% | Nov 26, 2024 | Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user ... |
| CVE-2024-11002 | MEDIUM | 6.3 | 0.6% | Nov 26, 2024 | The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_sh... |
| CVE-2024-10857 | MEDIUM | 6.5 | 0.8% | Nov 26, 2024 | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to... |
| CVE-2024-10781 | HIGH | 7.5 | 3.8% | Nov 26, 2024 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi... |
| CVE-2024-10570 | HIGH | 7.5 | 0.5% | Nov 26, 2024 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an auth... |
| CVE-2024-10542 | HIGH | 7.5 | 15.2% | Nov 26, 2024 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugi... |
| CVE-2024-10471 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-53278 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin us... |
| CVE-2024-49353 | MEDIUM | 5.9 | 0.3% | Nov 26, 2024 | IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to re... |
| CVE-2024-49351 | MEDIUM | 5.5 | 0.1% | Nov 26, 2024 | IBM Workload Scheduler 9.5, 10.1, and 10.2 stores user credentials in plain text which can be read by a local user. |
| CVE-2024-11418 | MEDIUM | 6.1 | 0.3% | Nov 26, 2024 | The Additional Order Filters for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th... |
| CVE-2024-11342 | MEDIUM | 6.1 | 0.2% | Nov 26, 2024 | The Skt NURCaptcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2024-49597 | HIGH | 7.2 | 0.6% | Nov 26, 2024 | Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Atte... |
| CVE-2024-49596 | MEDIUM | 6.5 | 0.4% | Nov 26, 2024 | Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged ... |
| CVE-2024-49595 | MEDIUM | 4.9 | 0.5% | Nov 26, 2024 | Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability... |
| CVE-2024-11678 | MEDIUM | 5.4 | 0.5% | Nov 26, 2024 | A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnera... |
| CVE-2024-11677 | MEDIUM | 5.4 | 0.5% | Nov 26, 2024 | A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affec... |
| CVE-2024-10729 | HIGH | 8.8 | 0.5% | Nov 26, 2024 | The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now