2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0126 | HIGH | 8.2 | 0.3% | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to esca... |
| CVE-2024-0121 | HIGH | 7.8 | 0.4% | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use... |
| CVE-2024-0120 | HIGH | 7.8 | 0.4% | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use... |
| CVE-2024-0119 | HIGH | 7.8 | 0.4% | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use... |
| CVE-2024-0118 | HIGH | 7.8 | 0.4% | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use... |
| CVE-2024-0117 | HIGH | 7.8 | 0.4% | Oct 26, 2024 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular use... |
| CVE-2024-9456 | MEDIUM | 6.4 | 0.3% | Oct 26, 2024 | The WP Awesome Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi... |
| CVE-2024-8870 | MEDIUM | 6.1 | 0.5% | Oct 26, 2024 | The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Reflected Cross-Si... |
| CVE-2024-9933 | CRITICAL | 9.8 | 1.9% | Oct 26, 2024 | The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.10.1. T... |
| CVE-2024-9932 | CRITICAL | 9.8 | 37.8% | Oct 26, 2024 | The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio... |
| CVE-2024-9931 | CRITICAL | 9.8 | 0.5% | Oct 26, 2024 | The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0.... |
| CVE-2024-9930 | CRITICAL | 9.8 | 0.5% | Oct 26, 2024 | The Extensions by HocWP Team plugin for WordPress is vulnerable to authentication bypass in versions up to, and includin... |
| CVE-2024-9890 | HIGH | 8.8 | 1.0% | Oct 26, 2024 | The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. Th... |
| CVE-2024-9626 | MEDIUM | 4.3 | 0.3% | Oct 26, 2024 | The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2024-9613 | MEDIUM | 6.1 | 0.4% | Oct 26, 2024 | The FormFacade – WordPress plugin for Google Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-9475 | HIGH | 7.2 | 0.5% | Oct 26, 2024 | The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection ... |
| CVE-2024-9462 | MEDIUM | 4.8 | 0.3% | Oct 26, 2024 | The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-9454 | MEDIUM | 6.4 | 0.3% | Oct 26, 2024 | The PriPre plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,... |
| CVE-2024-10091 | MEDIUM | 5.4 | 0.3% | Oct 26, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Compari... |
| CVE-2024-47821 | LOW | 2.3 | 0.7% | Oct 25, 2024 | pyLoad is a free and open-source Download Manager. The folder `/.pyload/scripts` has scripts which are run when certain ... |
| CVE-2024-48239 | MEDIUM | 4.8 | 0.2% | Oct 25, 2024 | An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't pr... |
| CVE-2024-48238 | MEDIUM | 4.7 | 0.3% | Oct 25, 2024 | WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the paren... |
| CVE-2024-48237 | CRITICAL | 9.8 | 0.4% | Oct 25, 2024 | WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php. |
| CVE-2024-48236 | MEDIUM | 6.5 | 0.7% | Oct 25, 2024 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the writ... |
| CVE-2024-48235 | MEDIUM | 6.5 | 0.7% | Oct 25, 2024 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now