2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51510 | MEDIUM | 5.5 | 0.1% | Nov 5, 2024 | Out-of-bounds access vulnerability in the logo module Impact: Successful exploitation of this vulnerability may affect s... |
| CVE-2024-10711 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-10114 | HIGH | 8.1 | 0.5% | Nov 5, 2024 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and in... |
| CVE-2024-47797 | HIGH | 7.8 | 0.2% | Nov 5, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens... |
| CVE-2024-47404 | HIGH | 7.8 | 0.2% | Nov 5, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens... |
| CVE-2024-47402 | MEDIUM | 5.5 | 0.1% | Nov 5, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read. |
| CVE-2024-47137 | HIGH | 7.8 | 0.2% | Nov 5, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens... |
| CVE-2024-10097 | HIGH | 8.1 | 0.7% | Nov 5, 2024 | The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to... |
| CVE-2024-9883 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-9689 | MEDIUM | 4.3 | 0.2% | Nov 5, 2024 | The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow at... |
| CVE-2024-9459 | HIGH | 8.8 | 2.1% | Nov 5, 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in re... |
| CVE-2024-7877 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not... |
| CVE-2024-7876 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not... |
| CVE-2024-5578 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-10810 | HIGH | 7.5 | 0.5% | Nov 5, 2024 | A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an ... |
| CVE-2024-10809 | HIGH | 7.5 | 0.5% | Nov 5, 2024 | A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some ... |
| CVE-2024-10808 | HIGH | 7.5 | 0.5% | Nov 5, 2024 | A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability ... |
| CVE-2024-10807 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue aff... |
| CVE-2024-10340 | MEDIUM | 6.4 | 0.3% | Nov 5, 2024 | The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'scu' short... |
| CVE-2024-10806 | MEDIUM | 4.8 | 0.4% | Nov 5, 2024 | A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulner... |
| CVE-2024-51498 | MEDIUM | 6 | 0.5% | Nov 5, 2024 | cobalt is a media downloader that doesn't piss you off. A malicious cobalt instance could serve links with the `javascri... |
| CVE-2024-50346 | MEDIUM | 5.1 | 0.6% | Nov 5, 2024 | WebFeed is a lightweight web feed reader extension for Firefox/Chrome. Multiple HTML injection vulnerabilities in WebFee... |
| CVE-2024-32870 | MEDIUM | 5.8 | 0.7% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and ... |
| CVE-2024-31998 | HIGH | 8.8 | 0.2% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This i... |
| CVE-2024-31448 | MEDIUM | 6.1 | 0.3% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-sit... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now