2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38002 | HIGH | 8.8 | 0.6% | Oct 22, 2024 | The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1... |
| CVE-2024-26273 | HIGH | 8.8 | 0.3% | Oct 22, 2024 | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, an... |
| CVE-2024-26272 | HIGH | 8.8 | 0.3% | Oct 22, 2024 | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, an... |
| CVE-2024-26271 | HIGH | 8.8 | 0.3% | Oct 22, 2024 | Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, a... |
| CVE-2024-50312 | MEDIUM | 5.3 | 0.5% | Oct 22, 2024 | A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allow... |
| CVE-2024-50311 | MEDIUM | 6.5 | 0.6% | Oct 22, 2024 | A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batchi... |
| CVE-2024-10234 | HIGH | 7.3 | 0.6% | Oct 22, 2024 | A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. Th... |
| CVE-2024-9050 | HIGH | 7.8 | 0.5% | Oct 22, 2024 | A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to proper... |
| CVE-2024-9231 | MEDIUM | 6.1 | 0.4% | Oct 22, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ... |
| CVE-2024-10189 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-9987 | HIGH | 8.8 | 0.4% | Oct 22, 2024 | A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv func... |
| CVE-2024-35308 | HIGH | 8.8 | 0.6% | Oct 22, 2024 | A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. Thi... |
| CVE-2024-9591 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | The Category and Taxonomy Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_category_ima... |
| CVE-2024-9590 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image me... |
| CVE-2024-9589 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_met... |
| CVE-2024-9588 | MEDIUM | 5.4 | 0.2% | Oct 22, 2024 | The Category and Taxonomy Meta Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to... |
| CVE-2024-9541 | MEDIUM | 4.3 | 0.3% | Oct 22, 2024 | The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to... |
| CVE-2024-9627 | HIGH | 7.3 | 0.4% | Oct 22, 2024 | The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing... |
| CVE-2024-8852 | MEDIUM | 5.3 | 1.2% | Oct 22, 2024 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi... |
| CVE-2024-10003 | MEDIUM | 6.3 | 0.4% | Oct 22, 2024 | The Rover IDX plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing... |
| CVE-2024-10002 | HIGH | 8.8 | 0.5% | Oct 22, 2024 | The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. ... |
| CVE-2024-9677 | HIGH | 7.8 | 0.2% | Oct 22, 2024 | The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version ... |
| CVE-2024-8901 | HIGH | 7.5 | 0.4% | Oct 22, 2024 | The AWS ALB Route Directive Adapter For Istio repo https://github.com/awslabs/aws-alb-route-directive-adapter-for-istio... |
| CVE-2024-10125 | HIGH | 7.5 | 0.3% | Oct 22, 2024 | The Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#vali... |
| CVE-2024-47224 | MEDIUM | 6.5 | 0.3% | Oct 21, 2024 | A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.20... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now