2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49308 | HIGH | 7.1 | 0.3% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toast Plugins Anim... |
| CVE-2024-49307 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpseek Admin Manag... |
| CVE-2024-49302 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in portfoliohub WordP... |
| CVE-2024-49301 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sinan Yorulmaz G M... |
| CVE-2024-49298 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group P... |
| CVE-2024-49296 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JC Custom Add to C... |
| CVE-2024-49295 | MEDIUM | 5.9 | 0.3% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PressTigers Simple... |
| CVE-2024-49292 | MEDIUM | 5.4 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclu... |
| CVE-2024-49289 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gora Tech L... |
| CVE-2024-10101 | MEDIUM | 5.4 | 0.3% | Oct 17, 2024 | A stored cross-site scripting (XSS) vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability oc... |
| CVE-2024-10100 | HIGH | 7.5 | 0.6% | Oct 17, 2024 | A path traversal vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability is due to improper ha... |
| CVE-2024-10099 | MEDIUM | 6.1 | 0.3% | Oct 17, 2024 | A stored cross-site scripting (XSS) vulnerability exists in comfyanonymous/comfyui version 0.2.2 and possibly earlier. T... |
| CVE-2024-49400 | CRITICAL | 9.8 | 0.4% | Oct 17, 2024 | Tacquito prior to commit 07b49d1358e6ec0b5aa482fcd284f509191119e2 was not properly performing regex matches on authorize... |
| CVE-2024-49322 | CRITICAL | 9.8 | 0.5% | Oct 17, 2024 | Incorrect Privilege Assignment vulnerability in CodePassenger Job Board Manager for WordPress jemployee allows Privilege... |
| CVE-2024-49318 | CRITICAL | 9.8 | 0.5% | Oct 17, 2024 | Deserialization of Untrusted Data vulnerability in Scott My Reading Library my-reading-library allows Object Injection.T... |
| CVE-2024-49317 | HIGH | 7.5 | 0.5% | Oct 17, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-49314 | CRITICAL | 10 | 0.5% | Oct 17, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in jiangqie JiangQie Free Mini Program jiangqie-free-mini-... |
| CVE-2024-49313 | HIGH | 7.1 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in rudestan VKontakte Wall Post vkontakte-wall-post allows Stored XSS.Th... |
| CVE-2024-49312 | HIGH | 8.6 | 0.2% | Oct 17, 2024 | Server-Side Request Forgery (SSRF) vulnerability in WisdmLabs Edwiser Bridge edwiser-bridge.This issue affects Edwiser B... |
| CVE-2024-49305 | CRITICAL | 9.3 | 0.4% | Oct 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Email Ve... |
| CVE-2024-49304 | MEDIUM | 5.4 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Stored XSS.T... |
| CVE-2024-49299 | HIGH | 7.6 | 0.4% | Oct 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Surfer Surfer surf... |
| CVE-2024-49297 | HIGH | 8.5 | 0.4% | Oct 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in zohocrm Zoho CRM L... |
| CVE-2024-49291 | CRITICAL | 10 | 0.5% | Oct 17, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Gora Tech LLC Cooked Pro.This issue affects Cooked Pro:... |
| CVE-2024-49287 | HIGH | 7.5 | 0.6% | Oct 17, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in mh6webentwicklung PDF-Re... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now