2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10260 | MEDIUM | 6.1 | 0.3% | Nov 15, 2024 | The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, a... |
| CVE-2024-10113 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
| CVE-2024-9609 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-... |
| CVE-2024-10897 | MEDIUM | 4.3 | 0.3% | Nov 15, 2024 | The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing c... |
| CVE-2024-10924 | CRITICAL | 9.8 | 81.7% | Nov 15, 2024 | The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass ... |
| CVE-2024-11120 | CRITICAL | 9.8 | 28.6% | Nov 15, 2024 | Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit t... |
| CVE-2024-52613 | MEDIUM | 5.5 | 0.2% | Nov 14, 2024 | A heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Servic... |
| CVE-2024-52308 | CRITICAL | 9.6 | 0.9% | Nov 14, 2024 | The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH serve... |
| CVE-2024-49778 | HIGH | 8.8 | 0.6% | Nov 14, 2024 | A heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service ... |
| CVE-2024-49777 | HIGH | 8.8 | 0.6% | Nov 14, 2024 | A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service ... |
| CVE-2024-49776 | MEDIUM | 6.5 | 0.4% | Nov 14, 2024 | A negative-size-param in tsMuxer version nightly-2024-04-05-01-53-02 allows attackers to cause Denial of Service (DoS) v... |
| CVE-2024-41217 | MEDIUM | 6.5 | 0.4% | Nov 14, 2024 | A heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service ... |
| CVE-2024-41209 | HIGH | 8.8 | 0.6% | Nov 14, 2024 | A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service ... |
| CVE-2024-41206 | MEDIUM | 6.5 | 0.4% | Nov 14, 2024 | A stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disc... |
| CVE-2024-51679 | MEDIUM | 6.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue aff... |
| CVE-2024-51659 | HIGH | 7.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XS... |
| CVE-2024-51658 | HIGH | 7.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.Thi... |
| CVE-2024-51156 | MEDIUM | 4.7 | 0.2% | Nov 14, 2024 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/... |
| CVE-2024-50968 | HIGH | 7.5 | 0.8% | Nov 14, 2024 | A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.... |
| CVE-2024-48974 | CRITICAL | 9.3 | 0.2% | Nov 14, 2024 | The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for ... |
| CVE-2024-48973 | CRITICAL | 9.3 | 0.2% | Nov 14, 2024 | The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and rece... |
| CVE-2024-48971 | CRITICAL | 9.3 | 0.2% | Nov 14, 2024 | The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This c... |
| CVE-2024-48970 | CRITICAL | 9.3 | 0.2% | Nov 14, 2024 | The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and r... |
| CVE-2024-48967 | CRITICAL | 10 | 0.6% | Nov 14, 2024 | The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activit... |
| CVE-2024-48966 | CRITICAL | 10 | 0.7% | Nov 14, 2024 | The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now