2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9351 | MEDIUM | 4.3 | 0.2% | Oct 17, 2024 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site... |
| CVE-2024-5429 | HIGH | 7.6 | 0.5% | Oct 17, 2024 | The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputtin... |
| CVE-2024-9347 | MEDIUM | 6.1 | 0.5% | Oct 17, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi... |
| CVE-2024-9263 | CRITICAL | 9.8 | 1.1% | Oct 17, 2024 | The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable... |
| CVE-2024-8719 | MEDIUM | 6.1 | 0.3% | Oct 17, 2024 | The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like... |
| CVE-2024-7417 | MEDIUM | 4.3 | 0.4% | Oct 17, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t... |
| CVE-2024-49593 | MEDIUM | 5.3 | 0.5% | Oct 17, 2024 | In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the ... |
| CVE-2024-9940 | MEDIUM | 4.3 | 0.4% | Oct 17, 2024 | The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.... |
| CVE-2024-9863 | CRITICAL | 9.8 | 0.6% | Oct 17, 2024 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up ... |
| CVE-2024-9862 | CRITICAL | 9.8 | 0.6% | Oct 17, 2024 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in ve... |
| CVE-2024-9861 | HIGH | 8.1 | 0.6% | Oct 17, 2024 | The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up... |
| CVE-2024-9240 | MEDIUM | 6.1 | 0.4% | Oct 17, 2024 | The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a... |
| CVE-2024-9215 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu... |
| CVE-2024-45767 | MEDIUM | 6.5 | 0.3% | Oct 17, 2024 | Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used... |
| CVE-2024-45766 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code In... |
| CVE-2024-7994 | HIGH | 7.8 | 0.2% | Oct 16, 2024 | A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Stack-Based Buffer Overflow. A malicious... |
| CVE-2024-7993 | HIGH | 7.8 | 0.2% | Oct 16, 2024 | A maliciously crafted PDF file, when parsed through Autodesk Revit, may force an Out-of-Bounds Write vulnerability. A ma... |
| CVE-2024-48918 | HIGH | 8.1 | 0.4% | Oct 16, 2024 | RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prio... |
| CVE-2024-48758 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the compone... |
| CVE-2024-48180 | CRITICAL | 9.8 | 0.6% | Oct 16, 2024 | ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uplo... |
| CVE-2024-47889 | MEDIUM | 6.6 | 0.9% | Oct 16, 2024 | Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9... |
| CVE-2024-47888 | MEDIUM | 6.6 | 1.0% | Oct 16, 2024 | Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.... |
| CVE-2024-46213 | HIGH | 7.2 | 1.0% | Oct 16, 2024 | REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability. |
| CVE-2024-46212 | MEDIUM | 4.9 | 0.9% | Oct 16, 2024 | An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory tr... |
| CVE-2024-44762 | MEDIUM | 5.3 | 2.5% | Oct 16, 2024 | A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now