2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9888 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-9873 | MEDIUM | 5.4 | 0.3% | Oct 16, 2024 | The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordP... |
| CVE-2024-10018 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any une... |
| CVE-2024-9891 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due... |
| CVE-2024-9652 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all... |
| CVE-2024-9649 | MEDIUM | 4.3 | 0.2% | Oct 16, 2024 | The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request For... |
| CVE-2024-9647 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all version... |
| CVE-2024-9634 | CRITICAL | 9.8 | 1.4% | Oct 16, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ... |
| CVE-2024-9521 | MEDIUM | 6.4 | 0.3% | Oct 16, 2024 | The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and i... |
| CVE-2024-9305 | CRITICAL | 9.8 | 0.7% | Oct 16, 2024 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in... |
| CVE-2024-9105 | CRITICAL | 9.8 | 0.6% | Oct 16, 2024 | The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This... |
| CVE-2024-9104 | MEDIUM | 5.6 | 0.3% | Oct 16, 2024 | The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. ... |
| CVE-2024-8787 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of... |
| CVE-2024-8541 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin fo... |
| CVE-2024-49340 | HIGH | 8.8 | 0.2% | Oct 16, 2024 | IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malic... |
| CVE-2024-38204 | MEDIUM | 6.5 | 1.0% | Oct 15, 2024 | Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. |
| CVE-2024-38190 | HIGH | 8.6 | 1.1% | Oct 15, 2024 | Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a netwo... |
| CVE-2024-38139 | HIGH | 8.8 | 0.8% | Oct 15, 2024 | Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. |
| CVE-2024-45085 | HIGH | 7.5 | 0.6% | Oct 15, 2024 | IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an un... |
| CVE-2024-10004 | CRITICAL | 9.1 | 0.4% | Oct 15, 2024 | Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in so... |
| CVE-2024-9966 | MEDIUM | 5.3 | 0.3% | Oct 15, 2024 | Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass ... |
| CVE-2024-9965 | HIGH | 8.8 | 0.4% | Oct 15, 2024 | Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker wh... |
| CVE-2024-9964 | MEDIUM | 4.3 | 0.3% | Oct 15, 2024 | Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced... |
| CVE-2024-9963 | MEDIUM | 4.3 | 0.3% | Oct 15, 2024 | Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convince... |
| CVE-2024-9962 | MEDIUM | 4.3 | 0.3% | Oct 15, 2024 | Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convin... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now