2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7481 | HIGH | 8.8 | 0.3% | Sep 25, 2024 | Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe ... |
| CVE-2024-7479 | HIGH | 8.8 | 0.4% | Sep 25, 2024 | Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe comp... |
| CVE-2024-45817 | HIGH | 7.3 | 0.5% | Sep 25, 2024 | In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status regis... |
| CVE-2024-31146 | HIGH | 7.5 | 0.2% | Sep 25, 2024 | When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system ... |
| CVE-2024-31145 | HIGH | 7.5 | 0.2% | Sep 25, 2024 | Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reportin... |
| CVE-2024-9169 | MEDIUM | 4.8 | 0.3% | Sep 25, 2024 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all v... |
| CVE-2024-8175 | HIGH | 7.5 | 0.6% | Sep 25, 2024 | An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS. |
| CVE-2024-47303 | MEDIUM | 5.4 | 0.2% | Sep 25, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh ... |
| CVE-2024-40761 | MEDIUM | 5.3 | 0.7% | Sep 25, 2024 | Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using ... |
| CVE-2024-23454 | MEDIUM | 6.2 | 0.4% | Sep 25, 2024 | Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be pres... |
| CVE-2024-8910 | MEDIUM | 4.3 | 0.3% | Sep 25, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ... |
| CVE-2024-8678 | MEDIUM | 5.3 | 0.3% | Sep 25, 2024 | The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-8290 | HIGH | 8.8 | 0.6% | Sep 25, 2024 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is... |
| CVE-2024-3866 | MEDIUM | 6.1 | 0.3% | Sep 25, 2024 | The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Re... |
| CVE-2024-8658 | MEDIUM | 5.3 | 0.3% | Sep 25, 2024 | The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo... |
| CVE-2024-7892 | MEDIUM | 4.3 | 0.2% | Sep 25, 2024 | The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2024-7878 | MEDIUM | 4.8 | 0.4% | Sep 25, 2024 | The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-6845 | MEDIUM | 5.3 | 1.1% | Sep 25, 2024 | The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, a... |
| CVE-2024-8668 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2024-8275 | CRITICAL | 9.8 | 49.7% | Sep 25, 2024 | The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_... |
| CVE-2024-8516 | MEDIUM | 4.3 | 0.4% | Sep 25, 2024 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an... |
| CVE-2024-8515 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget... |
| CVE-2024-8514 | HIGH | 7.2 | 1.0% | Sep 25, 2024 | The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up... |
| CVE-2024-7385 | HIGH | 7.2 | 1.3% | Sep 25, 2024 | The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all vers... |
| CVE-2024-9073 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The GutenGeek Free Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now