2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10691 | — | — | — | Nov 15, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-9530. Reason: This candidate is a r... |
| CVE-2024-11240 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unk... |
| CVE-2024-11239 | MEDIUM | 4.3 | 1.5% | Nov 15, 2024 | A vulnerability has been found in Landray EKP up to 16.0 and classified as critical. This vulnerability affects the func... |
| CVE-2024-11238 | MEDIUM | 5.3 | 5.6% | Nov 15, 2024 | A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPre... |
| CVE-2024-11237 | CRITICAL | 9.8 | 5.2% | Nov 15, 2024 | A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this... |
| CVE-2024-1240 | MEDIUM | 6.1 | 0.3% | Nov 15, 2024 | An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling o... |
| CVE-2024-1097 | MEDIUM | 5.4 | 0.3% | Nov 15, 2024 | A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs... |
| CVE-2024-11182 | MEDIUM | 6.1 | 17.1% | Nov 15, 2024 | An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail messag... |
| CVE-2024-10534 | CRITICAL | 9.8 | 0.4% | Nov 15, 2024 | Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Contr... |
| CVE-2024-10443 | CRITICAL | 9.8 | 28.4% | Nov 15, 2024 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager... |
| CVE-2024-0875 | MEDIUM | 4.8 | 0.4% | Nov 15, 2024 | A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malici... |
| CVE-2024-0787 | MEDIUM | 5.9 | 0.5% | Nov 15, 2024 | phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwo... |
| CVE-2024-8979 | MEDIUM | 5.7 | 0.5% | Nov 15, 2024 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo... |
| CVE-2024-8978 | MEDIUM | 5.7 | 0.5% | Nov 15, 2024 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo... |
| CVE-2024-10311 | HIGH | 8.8 | 0.4% | Nov 15, 2024 | The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and i... |
| CVE-2024-45784 | HIGH | 7.5 | 1.3% | Nov 15, 2024 | Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in tas... |
| CVE-2024-9529 | MEDIUM | 6.6 | 0.4% | Nov 15, 2024 | The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced C... |
| CVE-2024-8961 | MEDIUM | 5.4 | 0.3% | Nov 15, 2024 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo... |
| CVE-2024-10825 | MEDIUM | 6.1 | 0.3% | Nov 15, 2024 | The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ... |
| CVE-2024-10104 | MEDIUM | 5.9 | 0.3% | Nov 15, 2024 | The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high... |
| CVE-2024-9356 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | The Yotpo: Product & Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-42499 | MEDIUM | 5.3 | 0.6% | Nov 15, 2024 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior t... |
| CVE-2024-39610 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an... |
| CVE-2024-10793 | MEDIUM | 6.1 | 1.3% | Nov 15, 2024 | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all v... |
| CVE-2024-10582 | MEDIUM | 4.3 | 0.3% | Nov 15, 2024 | The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modifi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now