2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11179 | MEDIUM | 6.5 | 0.4% | Nov 20, 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via t... |
| CVE-2024-10891 | MEDIUM | 6.4 | 0.3% | Nov 20, 2024 | The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's... |
| CVE-2024-10665 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data d... |
| CVE-2024-11176 | MEDIUM | 5.3 | 0.4% | Nov 20, 2024 | Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access o... |
| CVE-2024-10127 | CRITICAL | 9.8 | 0.6% | Nov 20, 2024 | Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLD... |
| CVE-2024-10126 | MEDIUM | 4.3 | 0.4% | Nov 20, 2024 | Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7... |
| CVE-2024-52033 | MEDIUM | 5.3 | 0.4% | Nov 20, 2024 | Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware ver... |
| CVE-2024-48895 | HIGH | 8.8 | 1.0% | Nov 20, 2024 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo... |
| CVE-2024-47865 | MEDIUM | 5.3 | 0.4% | Nov 20, 2024 | Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earli... |
| CVE-2024-9239 | MEDIUM | 6.1 | 0.4% | Nov 20, 2024 | The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q... |
| CVE-2024-8726 | MEDIUM | 6.1 | 0.3% | Nov 20, 2024 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ... |
| CVE-2024-11277 | MEDIUM | 6.1 | 0.3% | Nov 20, 2024 | The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, an... |
| CVE-2024-10900 | HIGH | 8.1 | 0.5% | Nov 20, 2024 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2024-10899 | HIGH | 7.3 | 0.6% | Nov 20, 2024 | The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio... |
| CVE-2024-10855 | HIGH | 8.1 | 0.5% | Nov 20, 2024 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that... |
| CVE-2024-10365 | MEDIUM | 4.3 | 0.3% | Nov 20, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-9653 | MEDIUM | 6.1 | 0.3% | Nov 20, 2024 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Sit... |
| CVE-2024-52614 | MEDIUM | 4 | 0.2% | Nov 20, 2024 | Use of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions pri... |
| CVE-2024-10515 | LOW | 3.5 | 0.3% | Nov 20, 2024 | In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that... |
| CVE-2024-11278 | MEDIUM | 6.1 | 0.4% | Nov 20, 2024 | The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu... |
| CVE-2024-44309 | MEDIUM | 6.3 | 21.0% | Nov 20, 2024 | A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2... |
| CVE-2024-44308 | HIGH | 8.8 | 9.2% | Nov 20, 2024 | The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18... |
| CVE-2024-44307 | HIGH | 7.8 | 0.2% | Nov 20, 2024 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app ma... |
| CVE-2024-44306 | HIGH | 7.8 | 0.2% | Nov 20, 2024 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app ma... |
| CVE-2024-52595 | MEDIUM | 6.1 | 0.5% | Nov 19, 2024 | lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, th... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now