2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41605 | HIGH | 8.4 | 0.2% | Sep 26, 2024 | In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an updat... |
| CVE-2024-39319 | MEDIUM | 5.3 | 0.5% | Sep 26, 2024 | aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.... |
| CVE-2024-9155 | MEDIUM | 4.3 | 0.3% | Sep 26, 2024 | Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have no... |
| CVE-2024-30134 | HIGH | 7.5 | 0.2% | Sep 26, 2024 | The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Un... |
| CVE-2024-9177 | MEDIUM | 5.4 | 0.4% | Sep 26, 2024 | The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themedy_col, them... |
| CVE-2024-46330 | HIGH | 7.4 | 0.7% | Sep 26, 2024 | VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun ... |
| CVE-2024-46329 | HIGH | 8 | 0.8% | Sep 26, 2024 | VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object. |
| CVE-2024-46328 | HIGH | 8 | 0.2% | Sep 26, 2024 | VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts,... |
| CVE-2024-46327 | MEDIUM | 5.7 | 0.4% | Sep 26, 2024 | An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a dir... |
| CVE-2024-31899 | MEDIUM | 4.3 | 0.2% | Sep 26, 2024 | IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user ... |
| CVE-2024-8633 | MEDIUM | 4.8 | 0.3% | Sep 26, 2024 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-7108 | CRITICAL | 9.8 | 0.3% | Sep 26, 2024 | Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality ... |
| CVE-2024-7107 | HIGH | 7.5 | 0.3% | Sep 26, 2024 | Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath all... |
| CVE-2024-8725 | MEDIUM | 5.4 | 0.4% | Sep 26, 2024 | Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a... |
| CVE-2024-8704 | HIGH | 7.2 | 0.9% | Sep 26, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, a... |
| CVE-2024-8126 | HIGH | 8.8 | 0.9% | Sep 26, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php'... |
| CVE-2024-9199 | HIGH | 7.5 | 0.3% | Sep 26, 2024 | Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the ... |
| CVE-2024-9198 | MEDIUM | 5.4 | 0.2% | Sep 26, 2024 | Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored X... |
| CVE-2024-9173 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2024-9127 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter i... |
| CVE-2024-9125 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to... |
| CVE-2024-9117 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ... |
| CVE-2024-9115 | MEDIUM | 5.4 | 0.3% | Sep 26, 2024 | The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ... |
| CVE-2024-9025 | MEDIUM | 5.3 | 0.4% | Sep 26, 2024 | The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data d... |
| CVE-2024-8872 | MEDIUM | 6.1 | 0.4% | Sep 26, 2024 | The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now