2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8735 | MEDIUM | 6.1 | 0.5% | Nov 22, 2024 | The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use... |
| CVE-2024-11601 | HIGH | 8.1 | 0.3% | Nov 22, 2024 | The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider... |
| CVE-2024-11381 | MEDIUM | 6.4 | 0.7% | Nov 22, 2024 | The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' short... |
| CVE-2024-11355 | MEDIUM | 4.3 | 0.5% | Nov 22, 2024 | The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data ... |
| CVE-2024-11225 | MEDIUM | 6.1 | 0.5% | Nov 22, 2024 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripti... |
| CVE-2024-11104 | HIGH | 8.1 | 0.7% | Nov 22, 2024 | The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider... |
| CVE-2024-10666 | MEDIUM | 4.3 | 0.4% | Nov 22, 2024 | The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all ve... |
| CVE-2024-10034 | MEDIUM | 5.5 | 0.4% | Nov 22, 2024 | The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga... |
| CVE-2024-38296 | MEDIUM | 4.4 | 0.2% | Nov 22, 2024 | Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain ... |
| CVE-2024-47142 | MEDIUM | 5.5 | 0.3% | Nov 22, 2024 | AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue wi... |
| CVE-2024-45837 | MEDIUM | 5.4 | 0.3% | Nov 22, 2024 | Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A networ... |
| CVE-2024-39290 | MEDIUM | 6.5 | 0.4% | Nov 22, 2024 | Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticate... |
| CVE-2024-31408 | HIGH | 8 | 1.1% | Nov 22, 2024 | OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker... |
| CVE-2024-52056 | MEDIUM | 6.5 | 0.7% | Nov 21, 2024 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any... |
| CVE-2024-52055 | MEDIUM | 4.9 | 1.0% | Nov 21, 2024 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any f... |
| CVE-2024-52054 | LOW | 2.7 | 0.7% | Nov 21, 2024 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an ... |
| CVE-2024-52053 | CRITICAL | 9.6 | 0.6% | Nov 21, 2024 | Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated att... |
| CVE-2024-52052 | HIGH | 7.2 | 0.5% | Nov 21, 2024 | Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom ap... |
| CVE-2024-52616 | MEDIUM | 5.3 | 0.7% | Nov 21, 2024 | A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementi... |
| CVE-2024-52615 | MEDIUM | 5.3 | 0.6% | Nov 21, 2024 | A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies at... |
| CVE-2024-51367 | CRITICAL | 9.8 | 0.8% | Nov 21, 2024 | An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attacke... |
| CVE-2024-51366 | CRITICAL | 9.8 | 0.8% | Nov 21, 2024 | An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbi... |
| CVE-2024-51365 | — | — | — | Nov 21, 2024 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2024-51364 | HIGH | 8.8 | 0.7% | Nov 21, 2024 | An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a... |
| CVE-2024-49588 | MEDIUM | 6.8 | 0.3% | Nov 21, 2024 | Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now