2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51939 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Santhosh veer Styl... |
| CVE-2024-33231 | MEDIUM | 5.4 | 0.4% | Nov 18, 2024 | Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a c... |
| CVE-2024-52587 | HIGH | 8.8 | 2.7% | Nov 18, 2024 | StepSecurity's Harden-Runner provides network egress filtering and runtime security for GitHub-hosted and self-hosted ru... |
| CVE-2024-52418 | HIGH | 7.1 | 0.3% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CactusThemes Gamep... |
| CVE-2024-52417 | HIGH | 7.1 | 0.3% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldThemes ReConst... |
| CVE-2024-52394 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in verkkovaraani Prin... |
| CVE-2024-52390 | MEDIUM | 4.9 | 0.5% | Nov 18, 2024 | Path Traversal: '.../...//' vulnerability in Greg Ross CYAN Backup cyan-backup allows Path Traversal.This issue affects ... |
| CVE-2024-52389 | MEDIUM | 5.4 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpjobportal WP Job... |
| CVE-2024-52349 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Md. Shiddikur Rahm... |
| CVE-2024-52348 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Extensions AA A... |
| CVE-2024-52347 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpwebsitecreator W... |
| CVE-2024-52346 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JavierMendezPWG Si... |
| CVE-2024-52345 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RobertoAlicata ra_... |
| CVE-2024-52344 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeies Pvt Ltd Pr... |
| CVE-2024-52343 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutio... |
| CVE-2024-52342 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutio... |
| CVE-2024-52341 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Offshorent Solutio... |
| CVE-2024-51051 | CRITICAL | 9.8 | 0.5% | Nov 18, 2024 | AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account. |
| CVE-2024-21287 | HIGH | 7.5 | 1.5% | Nov 18, 2024 | Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Pro... |
| CVE-2024-10486 | MEDIUM | 5.3 | 0.9% | Nov 18, 2024 | The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and inclu... |
| CVE-2024-52585 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | Autolab is a course management service that enables auto-graded programming assignments. There is an HTML injection vuln... |
| CVE-2024-52584 | MEDIUM | 5.4 | 0.2% | Nov 18, 2024 | Autolab is a course management service that enables auto-graded programming assignments. There is a vulnerability in ver... |
| CVE-2024-52583 | HIGH | 8.2 | 0.2% | Nov 18, 2024 | The WesHacks GitHub repository provides the official Hackathon competition website source code for the Muweilah Wesgreen... |
| CVE-2024-52506 | MEDIUM | 6.5 | 0.6% | Nov 18, 2024 | Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and sched... |
| CVE-2024-52304 | HIGH | 7.5 | 0.6% | Nov 18, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python par... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now