2024 CVE Vulnerabilities
39,233 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50476 | CRITICAL | 9.8 | 1.2% | Oct 29, 2024 | Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege ... |
| CVE-2024-50475 | CRITICAL | 9.8 | 1.2% | Oct 29, 2024 | Missing Authorization vulnerability in Scott Gamon Signup Page signup-page allows Privilege Escalation.This issue affect... |
| CVE-2024-50473 | CRITICAL | 10 | 1.0% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-em... |
| CVE-2024-50427 | CRITICAL | 9.9 | 1.0% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects Surv... |
| CVE-2024-50426 | MEDIUM | 4.8 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak... |
| CVE-2024-50420 | CRITICAL | 10 | 0.5% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in aDirectory aDirectory adirectory allows Upload a Web Sh... |
| CVE-2024-50418 | MEDIUM | 6.5 | 0.2% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Time Slot Booking ... |
| CVE-2024-50415 | MEDIUM | 5.9 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagup Ads.txt & Ap... |
| CVE-2024-50414 | MEDIUM | 5.9 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Buttonizer Button ... |
| CVE-2024-50413 | MEDIUM | 5.9 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Javier Carazo Impo... |
| CVE-2024-50412 | MEDIUM | 5.9 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jules Colle Condit... |
| CVE-2024-50411 | MEDIUM | 4.8 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Ab... |
| CVE-2024-49642 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafasashi Todo Cus... |
| CVE-2024-47401 | HIGH | 7.5 | 0.4% | Oct 29, 2024 | Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from b... |
| CVE-2024-46872 | MEDIUM | 4.6 | 0.1% | Oct 29, 2024 | Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that... |
| CVE-2024-45477 | MEDIUM | 4.6 | 0.6% | Oct 29, 2024 | Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Paramete... |
| CVE-2024-22066 | MEDIUM | 6.5 | 0.3% | Oct 29, 2024 | There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated at... |
| CVE-2024-10048 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ... |
| CVE-2024-50494 | CRITICAL | 10 | 0.5% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-suda... |
| CVE-2024-50493 | CRITICAL | 10 | 1.0% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translat... |
| CVE-2024-50484 | CRITICAL | 10 | 0.5% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose... |
| CVE-2024-50482 | CRITICAL | 10 | 1.0% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-d... |
| CVE-2024-50480 | CRITICAL | 9.9 | 0.5% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in azexo Marketing Automation by AZEXO marketing-automatio... |
| CVE-2024-50052 | MEDIUM | 4.3 | 0.3% | Oct 29, 2024 | Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in a... |
| CVE-2024-10312 | MEDIUM | 4.3 | 0.4% | Oct 29, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now