2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47804MEDIUM4.3If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#is...
CVE-2024-47803MEDIUM4.3Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated ...
CVE-2024-33210MEDIUM5.4A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker t...
CVE-2024-33209MEDIUM5.4FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "A...
CVE-2024-47612LOW3.5DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifica...
CVE-2024-47611MEDIUM6.3XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinG...
CVE-2024-44193HIGH7.8A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attac...
CVE-2024-44097CRITICAL9.8According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the applica...
CVE-2024-9429CRITICAL9.8A vulnerability has been found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected b...
CVE-2024-8885HIGH8.8A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and...
CVE-2024-8038MEDIUM5.5Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection ...
CVE-2024-8037MEDIUM6.5Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the ...
CVE-2024-7558HIGH8JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on K...
CVE-2024-35294MEDIUM6.5An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administ...
CVE-2024-8505MEDIUM5.4The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-8282MEDIUM5.4The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’...
CVE-2024-44030HIGH7.2Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout M...
CVE-2024-44017HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board m...
CVE-2024-35293CRITICAL9.1An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or era...
CVE-2024-9378MEDIUM6.1The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter ...
CVE-2024-9344MEDIUM6.1The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaSc...
CVE-2024-9218MEDIUM6.1The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu...
CVE-2024-9225MEDIUM6.1The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu...
CVE-2024-9222MEDIUM6.1The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2024-9210MEDIUM6.1The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now