2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9373 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | The Elemenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t... |
| CVE-2024-9366 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | The Easy Menu Manager | WPZest plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in... |
| CVE-2024-9364 | MEDIUM | 4.3 | 0.4% | Oct 18, 2024 | The SendGrid for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability c... |
| CVE-2024-9361 | MEDIUM | 4.3 | 0.3% | Oct 18, 2024 | The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorize... |
| CVE-2024-9350 | MEDIUM | 6.1 | 0.4% | Oct 18, 2024 | The DPD Baltic Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_value' para... |
| CVE-2024-8916 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | The Suki Sites Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers... |
| CVE-2024-8790 | MEDIUM | 6.1 | 0.3% | Oct 18, 2024 | The Social Share With Floating Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o... |
| CVE-2024-8740 | MEDIUM | 6.1 | 0.4% | Oct 18, 2024 | The GetResponse Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o... |
| CVE-2024-10119 | CRITICAL | 9.8 | 0.9% | Oct 18, 2024 | The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attack... |
| CVE-2024-10049 | MEDIUM | 6.1 | 0.3% | Oct 18, 2024 | The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ param... |
| CVE-2024-10040 | MEDIUM | 4.3 | 0.2% | Oct 18, 2024 | The Infinite-Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2024-10014 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode ... |
| CVE-2024-9264 | HIGH | 8.8 | 97.8% | Oct 18, 2024 | The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input.... |
| CVE-2024-10118 | CRITICAL | 9.8 | 0.9% | Oct 18, 2024 | SECOM WRTR-304GN-304TW-UPSC does not properly filter user input in the specific functionality. Unauthenticated remote at... |
| CVE-2024-49023 | MEDIUM | 5.3 | 0.5% | Oct 18, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-43596 | HIGH | 8.8 | 1.0% | Oct 17, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-43595 | HIGH | 8.8 | 1.0% | Oct 17, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-43587 | HIGH | 8.1 | 0.9% | Oct 17, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-43580 | MEDIUM | 5.4 | 0.4% | Oct 17, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-43579 | HIGH | 8.3 | 0.7% | Oct 17, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-43578 | HIGH | 8.3 | 0.7% | Oct 17, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-43566 | CRITICAL | 9.8 | 1.1% | Oct 17, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-10093 | HIGH | 7.8 | 0.2% | Oct 17, 2024 | A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown funct... |
| CVE-2024-7316 | MEDIUM | 5.9 | 0.5% | Oct 17, 2024 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric CNC Series allows a remote unaut... |
| CVE-2024-33453 | HIGH | 8.1 | 1.0% | Oct 17, 2024 | Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to obtain sensitive information via the external... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now