2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10919 | CRITICAL | 9.8 | 4.9% | Nov 6, 2024 | A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an... |
| CVE-2024-6861 | HIGH | 7.5 | 0.7% | Nov 6, 2024 | A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is ena... |
| CVE-2024-35146 | MEDIUM | 5.4 | 0.2% | Nov 6, 2024 | IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This ... |
| CVE-2024-10916 | MEDIUM | 5.3 | 1.5% | Nov 6, 2024 | A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 202410... |
| CVE-2024-10082 | CRITICAL | 9 | 0.5% | Nov 6, 2024 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ... |
| CVE-2024-10081 | CRITICAL | 10 | 40.1% | Nov 6, 2024 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ... |
| CVE-2024-10915 | CRITICAL | 9.8 | 79.1% | Nov 6, 2024 | A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critic... |
| CVE-2024-10914 | CRITICAL | 9.8 | 97.4% | Nov 6, 2024 | A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as cri... |
| CVE-2024-10186 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode i... |
| CVE-2024-8323 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2024-10168 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Store... |
| CVE-2024-10715 | MEDIUM | 5.4 | 0.3% | Nov 6, 2024 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map b... |
| CVE-2024-9902 | MEDIUM | 6.3 | 0.2% | Nov 6, 2024 | A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace... |
| CVE-2024-8615 | CRITICAL | 9.8 | 0.8% | Nov 6, 2024 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2024-8614 | HIGH | 8.8 | 0.8% | Nov 6, 2024 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2024-9681 | MEDIUM | 6.5 | 2.0% | Nov 6, 2024 | When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it... |
| CVE-2024-52043 | MEDIUM | 5.3 | 0.4% | Nov 6, 2024 | Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavatio... |
| CVE-2024-9946 | HIGH | 8.1 | 0.6% | Nov 6, 2024 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authe... |
| CVE-2024-9307 | HIGH | 8.8 | 0.9% | Nov 6, 2024 | The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up ... |
| CVE-2024-6626 | MEDIUM | 5.3 | 0.4% | Nov 6, 2024 | The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized... |
| CVE-2024-10543 | MEDIUM | 4.3 | 0.3% | Nov 6, 2024 | The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability... |
| CVE-2024-10535 | MEDIUM | 5.3 | 0.4% | Nov 6, 2024 | The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-10020 | HIGH | 8.1 | 0.5% | Nov 6, 2024 | The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, an... |
| CVE-2024-9934 | MEDIUM | 6.1 | 0.3% | Nov 6, 2024 | The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back... |
| CVE-2024-7879 | MEDIUM | 4.8 | 0.3% | Nov 6, 2024 | The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high pr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now