2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10023 | HIGH | 8.8 | 0.5% | Oct 16, 2024 | A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. This vulnerability aff... |
| CVE-2024-8040 | HIGH | 7.7 | 0.3% | Oct 16, 2024 | An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R... |
| CVE-2024-6380 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX... |
| CVE-2024-10022 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an u... |
| CVE-2024-10021 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by th... |
| CVE-2024-8921 | MEDIUM | 6.4 | 0.4% | Oct 16, 2024 | The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i... |
| CVE-2024-9444 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up... |
| CVE-2024-9858 | HIGH | 7.8 | 0.1% | Oct 16, 2024 | There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windo... |
| CVE-2024-9540 | MEDIUM | 4.3 | 0.4% | Oct 16, 2024 | The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2024-9061 | CRITICAL | 9.8 | 51.3% | Oct 16, 2024 | The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary sho... |
| CVE-2024-45715 | MEDIUM | 5.2 | 0.3% | Oct 16, 2024 | The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to exis... |
| CVE-2024-45714 | MEDIUM | 4.1 | 0.8% | Oct 16, 2024 | Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a v... |
| CVE-2024-45711 | HIGH | 8.8 | 6.3% | Oct 16, 2024 | SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible dependi... |
| CVE-2024-45710 | HIGH | 7.8 | 0.3% | Oct 16, 2024 | SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This... |
| CVE-2024-45693 | HIGH | 8.8 | 0.5% | Oct 16, 2024 | Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing ... |
| CVE-2024-45462 | HIGH | 7.1 | 0.4% | Oct 16, 2024 | The logout operation in the CloudStack web interface does not expire the user session completely which is valid until ex... |
| CVE-2024-45461 | MEDIUM | 6.3 | 0.7% | Oct 16, 2024 | The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources,... |
| CVE-2024-45219 | HIGH | 8.5 | 1.2% | Oct 16, 2024 | Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and v... |
| CVE-2024-45217 | HIGH | 8.1 | 0.7% | Oct 16, 2024 | Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore... |
| CVE-2024-45216 | CRITICAL | 9.8 | 90.7% | Oct 16, 2024 | Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enable... |
| CVE-2024-9582 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an ac... |
| CVE-2024-8918 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and inc... |
| CVE-2024-8746 | HIGH | 8.8 | 0.6% | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing fi... |
| CVE-2024-8507 | HIGH | 8.8 | 0.2% | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2024-9937 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramete... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now