2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10332 | MEDIUM | 6.1 | 0.2% | Oct 24, 2024 | A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacke... |
| CVE-2024-10180 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2024-8959 | MEDIUM | 6.4 | 0.4% | Oct 24, 2024 | The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-5608 | HIGH | 8.1 | 1.3% | Oct 24, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature... |
| CVE-2024-49703 | MEDIUM | 6.5 | 0.2% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpE... |
| CVE-2024-49691 | HIGH | 7.6 | 0.4% | Oct 24, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Produc... |
| CVE-2024-49683 | MEDIUM | 5.3 | 0.3% | Oct 24, 2024 | Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp... |
| CVE-2024-49682 | MEDIUM | 6.1 | 0.3% | Oct 24, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allo... |
| CVE-2024-49681 | CRITICAL | 9.3 | 1.1% | Oct 24, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com W... |
| CVE-2024-9650 | MEDIUM | 5.4 | 0.4% | Oct 24, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip’ parameter in all... |
| CVE-2024-9214 | MEDIUM | 6.1 | 0.4% | Oct 24, 2024 | The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-10331 | HIGH | 8.8 | 0.5% | Oct 24, 2024 | A vulnerability, which was classified as critical, has been found in PHPGurukul Vehicle Record System 1.0. This issue af... |
| CVE-2024-10176 | MEDIUM | 6.4 | 0.3% | Oct 24, 2024 | The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_embe... |
| CVE-2024-8312 | MEDIUM | 5.4 | 0.5% | Oct 24, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17... |
| CVE-2024-6826 | MEDIUM | 6.5 | 0.5% | Oct 24, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.... |
| CVE-2024-8717 | MEDIUM | 6.1 | 0.4% | Oct 24, 2024 | The PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip plugin for WordPress is vulnerable to Reflected Cross-Si... |
| CVE-2024-10050 | MEDIUM | 4.3 | 0.5% | Oct 24, 2024 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to... |
| CVE-2024-9943 | MEDIUM | 6.3 | 0.2% | Oct 24, 2024 | The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross... |
| CVE-2024-9531 | MEDIUM | 4.3 | 0.3% | Oct 24, 2024 | The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unaut... |
| CVE-2024-8667 | MEDIUM | 4.3 | 0.3% | Oct 24, 2024 | The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable ... |
| CVE-2024-6049 | HIGH | 7.5 | 4.3% | Oct 24, 2024 | The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability... |
| CVE-2024-9865 | MEDIUM | 6.1 | 0.4% | Oct 24, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-9864 | MEDIUM | 6.1 | 0.3% | Oct 24, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-40595 | MEDIUM | 5.3 | 0.2% | Oct 24, 2024 | An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise b... |
| CVE-2024-9374 | MEDIUM | 6.1 | 0.3% | Oct 24, 2024 | The Terms descriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now