2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9696 | MEDIUM | 5.4 | 0.2% | Oct 12, 2024 | The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' sh... |
| CVE-2024-9595 | MEDIUM | 5.4 | 0.3% | Oct 12, 2024 | The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-8915 | MEDIUM | 6.4 | 0.3% | Oct 12, 2024 | The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions... |
| CVE-2024-8760 | MEDIUM | 5.3 | 0.5% | Oct 12, 2024 | The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to,... |
| CVE-2024-9756 | MEDIUM | 4.3 | 0.9% | Oct 12, 2024 | The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads ... |
| CVE-2024-9704 | MEDIUM | 5.4 | 0.2% | Oct 12, 2024 | The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_so... |
| CVE-2024-9047 | CRITICAL | 9.8 | 92.3% | Oct 12, 2024 | The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2... |
| CVE-2024-9824 | MEDIUM | 4.3 | 0.3% | Oct 12, 2024 | The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a... |
| CVE-2024-9778 | MEDIUM | 4.3 | 0.2% | Oct 12, 2024 | The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2024-9776 | MEDIUM | 4.8 | 0.3% | Oct 12, 2024 | The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a... |
| CVE-2024-9670 | MEDIUM | 6.1 | 0.3% | Oct 12, 2024 | The 2D Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wi... |
| CVE-2024-9656 | MEDIUM | 6.4 | 0.3% | Oct 12, 2024 | The Mynx Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers... |
| CVE-2024-9187 | MEDIUM | 4.3 | 0.3% | Oct 12, 2024 | The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check ... |
| CVE-2024-7489 | MEDIUM | 4.4 | 0.3% | Oct 12, 2024 | The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2024-9860 | MEDIUM | 5.4 | 0.3% | Oct 12, 2024 | The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing... |
| CVE-2024-9821 | HIGH | 8.8 | 1.2% | Oct 12, 2024 | The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missin... |
| CVE-2024-9592 | MEDIUM | 6.1 | 0.1% | Oct 12, 2024 | The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and... |
| CVE-2024-45754 | HIGH | 7.2 | 0.5% | Oct 11, 2024 | An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before... |
| CVE-2024-35522 | HIGH | 7.2 | 1.8% | Oct 11, 2024 | Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injectio... |
| CVE-2024-35517 | HIGH | 7.2 | 14.1% | Oct 11, 2024 | Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter. |
| CVE-2024-48938 | HIGH | 7.5 | 0.6% | Oct 11, 2024 | Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails... |
| CVE-2024-48937 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of t... |
| CVE-2024-48788 | HIGH | 7.5 | 0.6% | Oct 11, 2024 | An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firm... |
| CVE-2024-48772 | CRITICAL | 9.1 | 0.5% | Oct 11, 2024 | An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firm... |
| CVE-2024-46468 | HIGH | 7.5 | 0.4% | Oct 11, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now