2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34782 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-34781 | HIGH | 7.2 | 67.7% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-34780 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-32847 | HIGH | 7.2 | 3.1% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-32844 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-32841 | HIGH | 7.2 | 3.3% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-32839 | HIGH | 7.2 | 3.3% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-29211 | MEDIUM | 4.7 | 0.3% | Nov 13, 2024 | A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify se... |
| CVE-2024-10887 | MEDIUM | 6.4 | 0.4% | Nov 13, 2024 | The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes (ni... |
| CVE-2024-10854 | MEDIUM | 4.3 | 0.4% | Nov 13, 2024 | The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-10853 | MEDIUM | 4.3 | 0.3% | Nov 13, 2024 | The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-10852 | MEDIUM | 4.3 | 0.4% | Nov 13, 2024 | The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil... |
| CVE-2024-10851 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o... |
| CVE-2024-10850 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to... |
| CVE-2024-10778 | MEDIUM | 4.3 | 0.5% | Nov 13, 2024 | The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all ve... |
| CVE-2024-10717 | MEDIUM | 6.5 | 0.4% | Nov 13, 2024 | The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a de... |
| CVE-2024-10686 | — | — | — | Nov 13, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-51689. Reason: This candidate is a ... |
| CVE-2024-10629 | HIGH | 8.8 | 1.6% | Nov 13, 2024 | The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file ... |
| CVE-2024-10577 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | The 胖鼠采集(Fat Rat Collect) 微信知乎简书腾讯新闻列表分页采集, 还有自动采集、自动发布、自动标签、等多项功能。开源插件 plugin for WordPress is vulnerable to Reflected ... |
| CVE-2024-10038 | MEDIUM | 6.1 | 0.3% | Nov 13, 2024 | The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to... |
| CVE-2024-28731 | MEDIUM | 4.3 | 0.2% | Nov 12, 2024 | Cross Site Request Forgery vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.3... |
| CVE-2024-28730 | MEDIUM | 5.4 | 0.3% | Nov 12, 2024 | Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME al... |
| CVE-2024-28729 | CRITICAL | 9.8 | 0.6% | Nov 12, 2024 | An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to e... |
| CVE-2024-28728 | MEDIUM | 6.6 | 0.5% | Nov 12, 2024 | Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME al... |
| CVE-2024-28726 | HIGH | 8 | 8.1% | Nov 12, 2024 | An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to e... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now