2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45125 | MEDIUM | 4.3 | 0.5% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization v... |
| CVE-2024-45124 | MEDIUM | 5.3 | 0.6% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v... |
| CVE-2024-45123 | MEDIUM | 6.1 | 0.4% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scrip... |
| CVE-2024-45122 | MEDIUM | 4.3 | 0.5% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v... |
| CVE-2024-45121 | MEDIUM | 4.3 | 0.5% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v... |
| CVE-2024-45120 | LOW | 3.1 | 0.4% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use ... |
| CVE-2024-45119 | MEDIUM | 4.9 | 0.8% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forg... |
| CVE-2024-45118 | MEDIUM | 6.5 | 0.6% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v... |
| CVE-2024-45117 | HIGH | 7.6 | 0.9% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation... |
| CVE-2024-45116 | HIGH | 8.1 | 0.9% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS)... |
| CVE-2024-45115 | CRITICAL | 9.8 | 1.1% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication v... |
| CVE-2024-22068 | MEDIUM | 6.5 | 0.2% | Oct 10, 2024 | Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 6... |
| CVE-2024-9802 | MEDIUM | 5.3 | 0.2% | Oct 10, 2024 | The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The respons... |
| CVE-2024-9798 | MEDIUM | 5.3 | 0.2% | Oct 10, 2024 | The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for at... |
| CVE-2024-9796 | CRITICAL | 9.8 | 3.0% | Oct 10, 2024 | The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a... |
| CVE-2024-7049 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending ... |
| CVE-2024-6747 | HIGH | 7.5 | 0.4% | Oct 10, 2024 | Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to... |
| CVE-2024-9781 | HIGH | 7.5 | 0.3% | Oct 10, 2024 | AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet i... |
| CVE-2024-9780 | MEDIUM | 5.5 | 0.2% | Oct 10, 2024 | ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file |
| CVE-2024-9156 | HIGH | 7.5 | 0.4% | Oct 10, 2024 | The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping o... |
| CVE-2024-9520 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing ... |
| CVE-2024-9074 | MEDIUM | 5.4 | 0.2% | Oct 10, 2024 | The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve... |
| CVE-2024-9067 | MEDIUM | 4.3 | 0.3% | Oct 10, 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
| CVE-2024-9022 | HIGH | 7.2 | 0.9% | Oct 10, 2024 | The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘o... |
| CVE-2024-8477 | MEDIUM | 4.3 | 0.2% | Oct 10, 2024 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now