2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9685 | MEDIUM | 4.3 | 0.3% | Oct 10, 2024 | The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing c... |
| CVE-2024-9581 | HIGH | 7.3 | 0.4% | Oct 10, 2024 | The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i... |
| CVE-2024-9522 | HIGH | 8.8 | 0.5% | Oct 10, 2024 | The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.... |
| CVE-2024-9519 | HIGH | 7.2 | 0.5% | Oct 10, 2024 | The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check... |
| CVE-2024-9518 | CRITICAL | 9.8 | 0.5% | Oct 10, 2024 | The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to ins... |
| CVE-2024-9457 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up... |
| CVE-2024-9377 | MEDIUM | 6.1 | 0.4% | Oct 10, 2024 | The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Script... |
| CVE-2024-9205 | MEDIUM | 6.1 | 0.3% | Oct 10, 2024 | The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t... |
| CVE-2024-9072 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File... |
| CVE-2024-9066 | MEDIUM | 5.4 | 0.2% | Oct 10, 2024 | The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ... |
| CVE-2024-9065 | MEDIUM | 5.3 | 0.4% | Oct 10, 2024 | The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-9064 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v... |
| CVE-2024-9057 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2024-8987 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
| CVE-2024-8729 | MEDIUM | 6.1 | 0.3% | Oct 10, 2024 | The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add... |
| CVE-2024-8513 | MEDIUM | 5.3 | 0.4% | Oct 10, 2024 | The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable... |
| CVE-2024-7048 | MEDIUM | 5.4 | 0.4% | Oct 10, 2024 | In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/... |
| CVE-2024-48958 | HIGH | 7.8 | 0.6% | Oct 10, 2024 | execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a c... |
| CVE-2024-48957 | HIGH | 7.8 | 0.5% | Oct 10, 2024 | execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a c... |
| CVE-2024-48949 | CRITICAL | 9.1 | 0.5% | Oct 10, 2024 | The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(s... |
| CVE-2024-48942 | MEDIUM | 5.9 | 0.5% | Oct 10, 2024 | The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to eas... |
| CVE-2024-48941 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to byp... |
| CVE-2024-8264 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent... |
| CVE-2024-48933 | MEDIUM | 6.1 | 0.3% | Oct 9, 2024 | A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary we... |
| CVE-2024-7041 | MEDIUM | 6.5 | 0.4% | Oct 9, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerabili... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now