2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8444 | MEDIUM | 5.4 | 0.3% | Oct 30, 2024 | The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross... |
| CVE-2024-10223 | MEDIUM | 6.4 | 0.3% | Oct 30, 2024 | The WP Team – WordPress Team Member Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
| CVE-2024-10108 | HIGH | 7.2 | 0.4% | Oct 30, 2024 | The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ad... |
| CVE-2024-8871 | MEDIUM | 6.1 | 0.4% | Oct 30, 2024 | The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scr... |
| CVE-2024-10399 | MEDIUM | 4.3 | 0.4% | Oct 30, 2024 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2024-9886 | MEDIUM | 6.4 | 0.3% | Oct 30, 2024 | The WP Baidu Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'baidu_map' shortcod... |
| CVE-2024-9885 | MEDIUM | 6.4 | 0.3% | Oct 30, 2024 | The Widget or Sidebar Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'side... |
| CVE-2024-9884 | MEDIUM | 6.4 | 0.3% | Oct 30, 2024 | The T(-) Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tminus' shortcode... |
| CVE-2024-9846 | HIGH | 7.3 | 0.5% | Oct 30, 2024 | The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable to arbitrary shortcode ... |
| CVE-2024-8792 | MEDIUM | 6.1 | 0.4% | Oct 30, 2024 | The Subscribe to Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que... |
| CVE-2024-8627 | MEDIUM | 5.4 | 0.3% | Oct 30, 2024 | The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all ... |
| CVE-2024-10509 | CRITICAL | 9.8 | 0.8% | Oct 30, 2024 | A vulnerability, which was classified as critical, has been found in Codezips Online Institute Management System 1.0. Th... |
| CVE-2024-10507 | CRITICAL | 9.8 | 0.8% | Oct 30, 2024 | A vulnerability classified as critical was found in Codezips Free Exam Hall Seating Management System 1.0. This vulnerab... |
| CVE-2024-10506 | HIGH | 7.2 | 0.6% | Oct 30, 2024 | A vulnerability classified as critical has been found in code-projects Blood Bank System 1.0. This affects an unknown pa... |
| CVE-2024-10505 | HIGH | 7.2 | 0.7% | Oct 30, 2024 | A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of th... |
| CVE-2024-10503 | MEDIUM | 6.1 | 0.3% | Oct 30, 2024 | A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some ... |
| CVE-2024-10502 | HIGH | 8.8 | 0.5% | Oct 30, 2024 | A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function get... |
| CVE-2024-10501 | HIGH | 8.8 | 0.5% | Oct 30, 2024 | A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function findById of th... |
| CVE-2024-10500 | HIGH | 8.8 | 0.5% | Oct 30, 2024 | A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is some unkn... |
| CVE-2024-51568 | CRITICAL | 9.8 | 45.7% | Oct 29, 2024 | CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut... |
| CVE-2024-51567 | CRITICAL | 9.8 | 86.7% | Oct 29, 2024 | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas... |
| CVE-2024-51378 | CRITICAL | 9.8 | 94.8% | Oct 29, 2024 | getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t... |
| CVE-2024-50348 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | InstantCMS is a free and open source content management system. In photo upload function in the photo album page there i... |
| CVE-2024-9997 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted DWG file when parsed in acdb25.dll through Autodesk AutoCAD can force a Memory Corruption vulnerab... |
| CVE-2024-9996 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted DWG file, when parsed in acdb25.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vul... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now