2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10675 | MEDIUM | 6.1 | 0.4% | Nov 21, 2024 | The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up ... |
| CVE-2024-10671 | MEDIUM | 6.5 | 0.5% | Nov 21, 2024 | The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information E... |
| CVE-2024-10623 | MEDIUM | 6.1 | 0.4% | Nov 21, 2024 | The ForumEngine theme for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and... |
| CVE-2024-10532 | MEDIUM | 4.3 | 0.5% | Nov 21, 2024 | The Bard Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-10528 | MEDIUM | 4.3 | 0.6% | Nov 21, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2024-10522 | MEDIUM | 6.1 | 0.6% | Nov 21, 2024 | The Co-marquage service-public.fr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of... |
| CVE-2024-10482 | MEDIUM | 5.4 | 0.4% | Nov 21, 2024 | The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does n... |
| CVE-2024-10403 | HIGH | 7.5 | 0.6% | Nov 21, 2024 | Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFT... |
| CVE-2024-10400 | HIGH | 7.5 | 82.6% | Nov 21, 2024 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up t... |
| CVE-2024-10393 | MEDIUM | 5.3 | 0.6% | Nov 21, 2024 | The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6.... |
| CVE-2024-10316 | MEDIUM | 4.3 | 0.5% | Nov 21, 2024 | The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up ... |
| CVE-2024-10177 | MEDIUM | 6.4 | 0.6% | Nov 21, 2024 | The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's beds24-link... |
| CVE-2024-10172 | MEDIUM | 5.4 | 0.5% | Nov 21, 2024 | The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-10164 | MEDIUM | 6.4 | 0.5% | Nov 21, 2024 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-9875 | HIGH | 7.1 | 0.2% | Nov 21, 2024 | Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerabilit... |
| CVE-2024-52755 | MEDIUM | 4.9 | 0.8% | Nov 21, 2024 | D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the host_ip parameter in the ipsec_road_asp f... |
| CVE-2024-51151 | CRITICAL | 9.8 | 29.7% | Nov 21, 2024 | D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter ... |
| CVE-2024-52765 | CRITICAL | 9.8 | 11.2% | Nov 20, 2024 | H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter. |
| CVE-2024-52702 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to... |
| CVE-2024-52701 | MEDIUM | 5.4 | 0.2% | Nov 20, 2024 | A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execut... |
| CVE-2024-52677 | CRITICAL | 9.8 | 0.6% | Nov 20, 2024 | HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php. |
| CVE-2024-52581 | HIGH | 7.5 | 0.8% | Nov 20, 2024 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parse... |
| CVE-2024-49203 | — | — | 0.4% | Nov 20, 2024 | Querydsl 5.1.0 and OpenFeign Querydsl 6.8 allows SQL/HQL injection in orderBy in JPAQuery. NOTE: this is disputed by a Q... |
| CVE-2024-48986 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci pac... |
| CVE-2024-48984 | CRITICAL | 9.8 | 0.5% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now