2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9172 | MEDIUM | 5.4 | 0.3% | Oct 2, 2024 | The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver... |
| CVE-2024-8967 | MEDIUM | 5.4 | 0.3% | Oct 2, 2024 | The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File... |
| CVE-2024-8800 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and m... |
| CVE-2024-8254 | MEDIUM | 6.3 | 0.5% | Oct 2, 2024 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f... |
| CVE-2024-9333 | MEDIUM | 5.3 | 0.4% | Oct 2, 2024 | Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited am... |
| CVE-2024-9174 | MEDIUM | 5.4 | 0.3% | Oct 2, 2024 | Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI |
| CVE-2024-7315 | HIGH | 7.5 | 0.6% | Oct 2, 2024 | The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that ... |
| CVE-2024-7855 | HIGH | 8.8 | 15.0% | Oct 2, 2024 | The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in... |
| CVE-2024-45186 | CRITICAL | 9.8 | 0.6% | Oct 2, 2024 | FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials. |
| CVE-2024-33662 | HIGH | 7.5 | 0.3% | Oct 2, 2024 | Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function. |
| CVE-2024-21530 | MEDIUM | 4.5 | 0.1% | Oct 2, 2024 | Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, ... |
| CVE-2024-9407 | MEDIUM | 4.7 | 0.3% | Oct 1, 2024 | A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not pro... |
| CVE-2024-47609 | MEDIUM | 6.9 | 0.6% | Oct 1, 2024 | Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server ther... |
| CVE-2024-47528 | MEDIUM | 4.8 | 0.4% | Oct 1, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be ach... |
| CVE-2024-47527 | MEDIUM | 5.4 | 0.5% | Oct 1, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab... |
| CVE-2024-47526 | LOW | 2.4 | 0.4% | Oct 1, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulne... |
| CVE-2024-47525 | MEDIUM | 5.4 | 26.2% | Oct 1, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab... |
| CVE-2024-47524 | MEDIUM | 4.8 | 0.5% | Oct 1, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Gro... |
| CVE-2024-47523 | MEDIUM | 5.4 | 0.6% | Oct 1, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab... |
| CVE-2024-46084 | HIGH | 8 | 0.8% | Oct 1, 2024 | Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function. |
| CVE-2024-46082 | MEDIUM | 5.4 | 0.3% | Oct 1, 2024 | Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parame... |
| CVE-2024-46080 | HIGH | 8 | 0.7% | Oct 1, 2024 | Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function. |
| CVE-2024-9411 | MEDIUM | 5.3 | 0.3% | Oct 1, 2024 | A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admi... |
| CVE-2024-45999 | CRITICAL | 9.8 | 0.4% | Oct 1, 2024 | A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function loca... |
| CVE-2024-9355 | MEDIUM | 6.5 | 0.3% | Oct 1, 2024 | A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized b... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now