2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48023 | HIGH | 7.1 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rconnect305 Restau... |
| CVE-2024-48022 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SysBasics S... |
| CVE-2024-48021 | HIGH | 7.1 | 0.3% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Con... |
| CVE-2024-49320 | HIGH | 7.1 | 0.3% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dennis Encyclopedi... |
| CVE-2024-48047 | MEDIUM | 4.3 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Razon Komar Pal Linked Variation for WooCommerce linked-variation-for... |
| CVE-2024-48043 | HIGH | 7.6 | 0.4% | Oct 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPi... |
| CVE-2024-48038 | MEDIUM | 4.3 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in tuxlog wp-Monalisa wp-monalisa.This issue affects wp-Monalisa: from n... |
| CVE-2024-48024 | HIGH | 7.5 | 0.4% | Oct 17, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Fahad Mahmood Keep Backup Da... |
| CVE-2024-9898 | MEDIUM | 5.4 | 0.4% | Oct 17, 2024 | The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dd-parallax shortc... |
| CVE-2024-45713 | MEDIUM | 4.4 | 0.4% | Oct 17, 2024 | SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been... |
| CVE-2024-10068 | HIGH | 8.5 | 0.2% | Oct 17, 2024 | A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an ... |
| CVE-2024-9184 | HIGH | 7.2 | 0.4% | Oct 17, 2024 | The SendPulse Free Web Push plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and... |
| CVE-2024-8920 | MEDIUM | 6.4 | 0.4% | Oct 17, 2024 | The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo... |
| CVE-2024-49392 | MEDIUM | 4.8 | 0.2% | Oct 17, 2024 | Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acro... |
| CVE-2024-49391 | HIGH | 7.3 | 0.1% | Oct 17, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files ... |
| CVE-2024-49390 | HIGH | 7.3 | 0.2% | Oct 17, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files ... |
| CVE-2024-49389 | HIGH | 7.8 | 0.1% | Oct 17, 2024 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files ... |
| CVE-2024-49386 | MEDIUM | 5.7 | 0.2% | Oct 17, 2024 | Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows... |
| CVE-2024-10025 | CRITICAL | 9.1 | 0.7% | Oct 17, 2024 | A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By e... |
| CVE-2024-9951 | MEDIUM | 6.1 | 0.3% | Oct 17, 2024 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' paramete... |
| CVE-2024-3187 | MEDIUM | 5.9 | 0.5% | Oct 17, 2024 | This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6.... |
| CVE-2024-3186 | MEDIUM | 5.3 | 0.4% | Oct 17, 2024 | CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when ... |
| CVE-2024-3184 | MEDIUM | 5.9 | 0.5% | Oct 17, 2024 | Multiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when comp... |
| CVE-2024-9213 | MEDIUM | 6.1 | 0.4% | Oct 17, 2024 | The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du... |
| CVE-2024-9352 | MEDIUM | 4.3 | 0.2% | Oct 17, 2024 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now