2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47804 | MEDIUM | 4.3 | 0.7% | Oct 2, 2024 | If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#is... |
| CVE-2024-47803 | MEDIUM | 4.3 | 0.8% | Oct 2, 2024 | Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated ... |
| CVE-2024-33210 | MEDIUM | 5.4 | 0.6% | Oct 2, 2024 | A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker t... |
| CVE-2024-33209 | MEDIUM | 5.4 | 0.8% | Oct 2, 2024 | FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "A... |
| CVE-2024-47612 | LOW | 3.5 | 0.3% | Oct 2, 2024 | DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifica... |
| CVE-2024-47611 | MEDIUM | 6.3 | 0.7% | Oct 2, 2024 | XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinG... |
| CVE-2024-44193 | HIGH | 7.8 | 0.4% | Oct 2, 2024 | A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attac... |
| CVE-2024-44097 | CRITICAL | 9.8 | 0.2% | Oct 2, 2024 | According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the applica... |
| CVE-2024-9429 | CRITICAL | 9.8 | 0.6% | Oct 2, 2024 | A vulnerability has been found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected b... |
| CVE-2024-8885 | HIGH | 8.8 | 0.1% | Oct 2, 2024 | A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and... |
| CVE-2024-8038 | MEDIUM | 5.5 | 0.2% | Oct 2, 2024 | Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection ... |
| CVE-2024-8037 | MEDIUM | 6.5 | 0.2% | Oct 2, 2024 | Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the ... |
| CVE-2024-7558 | HIGH | 8 | 0.5% | Oct 2, 2024 | JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on K... |
| CVE-2024-35294 | MEDIUM | 6.5 | 0.4% | Oct 2, 2024 | An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administ... |
| CVE-2024-8505 | MEDIUM | 5.4 | 0.4% | Oct 2, 2024 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-8282 | MEDIUM | 5.4 | 0.3% | Oct 2, 2024 | The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’... |
| CVE-2024-44030 | HIGH | 7.2 | 0.6% | Oct 2, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout M... |
| CVE-2024-44017 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board m... |
| CVE-2024-35293 | CRITICAL | 9.1 | 0.6% | Oct 2, 2024 | An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or era... |
| CVE-2024-9378 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter ... |
| CVE-2024-9344 | MEDIUM | 6.1 | 0.3% | Oct 2, 2024 | The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaSc... |
| CVE-2024-9218 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu... |
| CVE-2024-9225 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu... |
| CVE-2024-9222 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres... |
| CVE-2024-9210 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now