2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8675 | MEDIUM | 4.3 | 0.3% | Oct 1, 2024 | The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2024-8632 | MEDIUM | 6.5 | 0.3% | Oct 1, 2024 | The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and mo... |
| CVE-2024-8548 | HIGH | 8.1 | 0.4% | Oct 1, 2024 | The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2024-7869 | HIGH | 7.2 | 0.4% | Oct 1, 2024 | The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i... |
| CVE-2024-7434 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via... |
| CVE-2024-7433 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 vi... |
| CVE-2024-7432 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 vi... |
| CVE-2024-8107 | MEDIUM | 5.4 | 0.3% | Oct 1, 2024 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers... |
| CVE-2024-8421 | — | — | — | Oct 1, 2024 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. |
| CVE-2024-21531 | MEDIUM | 5.3 | 0.9% | Oct 1, 2024 | All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigat... |
| CVE-2024-21489 | HIGH | 8.2 | 0.6% | Oct 1, 2024 | Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to m... |
| CVE-2024-0116 | MEDIUM | 6.5 | 0.4% | Oct 1, 2024 | NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing ... |
| CVE-2024-47295 | HIGH | 8.1 | 0.8% | Oct 1, 2024 | Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set ... |
| CVE-2024-9360 | CRITICAL | 9.8 | 0.8% | Oct 1, 2024 | A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been classified as critical. This a... |
| CVE-2024-8981 | HIGH | 7.1 | 0.5% | Oct 1, 2024 | The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query... |
| CVE-2024-9359 | CRITICAL | 9.8 | 0.8% | Oct 1, 2024 | A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by thi... |
| CVE-2024-9358 | MEDIUM | 5.9 | 0.7% | Oct 1, 2024 | A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability ... |
| CVE-2024-47560 | HIGH | 7.8 | 0.2% | Oct 1, 2024 | RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is ex... |
| CVE-2024-47396 | MEDIUM | 5.4 | 0.3% | Oct 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Ad... |
| CVE-2024-9194 | CRITICAL | 9.8 | 0.4% | Sep 30, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsof... |
| CVE-2024-45073 | MEDIUM | 4.8 | 0.2% | Sep 30, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p... |
| CVE-2024-7675 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A mali... |
| CVE-2024-7674 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer O... |
| CVE-2024-7673 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Ove... |
| CVE-2024-7672 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bou... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now