2024 CVE Vulnerabilities
39,233 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50447 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's ... |
| CVE-2024-50446 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FuturioWP Futurio ... |
| CVE-2024-50445 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in merkulove Selectio... |
| CVE-2024-50441 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CozyThemes Cozy Bl... |
| CVE-2024-50440 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Coyier CodeP... |
| CVE-2024-50439 | MEDIUM | 5.4 | 0.2% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force A... |
| CVE-2024-50438 | MEDIUM | 6.1 | 0.3% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church ... |
| CVE-2024-6245 | HIGH | 7.4 | 0.2% | Oct 28, 2024 | Use of Default Credentials vulnerability in Maruti Suzuki SmartPlay on Linux (Infotainment Hub modules) allows attacker ... |
| CVE-2024-49771 | MEDIUM | 5.3 | 0.5% | Oct 28, 2024 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch f... |
| CVE-2024-47827 | MEDIUM | 4.8 | 0.3% | Oct 28, 2024 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Due to ... |
| CVE-2024-42028 | HIGH | 8.8 | 0.2% | Oct 28, 2024 | A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (V... |
| CVE-2024-10469 | MEDIUM | 6.5 | 0.2% | Oct 28, 2024 | VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users. |
| CVE-2024-49761 | HIGH | 7.5 | 1.4% | Oct 28, 2024 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has ma... |
| CVE-2024-48291 | MEDIUM | 6.3 | 0.2% | Oct 28, 2024 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdm... |
| CVE-2024-45802 | HIGH | 7.5 | 45.3% | Oct 28, 2024 | Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premat... |
| CVE-2024-10450 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as cri... |
| CVE-2024-10449 | CRITICAL | 9.8 | 1.4% | Oct 28, 2024 | A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects a... |
| CVE-2024-10214 | LOW | 3.5 | 0.4% | Oct 28, 2024 | Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the ... |
| CVE-2024-50443 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultima... |
| CVE-2024-48191 | MEDIUM | 6.3 | 0.2% | Oct 28, 2024 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.p... |
| CVE-2024-34537 | MEDIUM | 4.9 | 0.7% | Oct 28, 2024 | TYPO3 before 13.3.1 allows denial of service (interface error) in the Bookmark Toolbar (ext:backend), exploitable by an ... |
| CVE-2024-10455 | HIGH | 7.5 | 0.4% | Oct 28, 2024 | Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block |
| CVE-2024-10448 | MEDIUM | 6.5 | 0.4% | Oct 28, 2024 | A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. ... |
| CVE-2024-8013 | LOW | 3.3 | 0.1% | Oct 28, 2024 | A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in express... |
| CVE-2024-50582 | MEDIUM | 5.4 | 0.3% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now