2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8623 | HIGH | 7.3 | 0.6% | Sep 24, 2024 | The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in al... |
| CVE-2024-8795 | HIGH | 8.8 | 0.3% | Sep 24, 2024 | The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-8738 | MEDIUM | 6.1 | 0.4% | Sep 24, 2024 | The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu... |
| CVE-2024-8716 | MEDIUM | 6.1 | 0.4% | Sep 24, 2024 | The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ... |
| CVE-2024-8662 | MEDIUM | 6.1 | 0.4% | Sep 24, 2024 | The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ... |
| CVE-2024-8657 | MEDIUM | 5.4 | 0.4% | Sep 24, 2024 | The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortc... |
| CVE-2024-8544 | MEDIUM | 6.1 | 0.5% | Sep 24, 2024 | The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the... |
| CVE-2024-8432 | MEDIUM | 4.3 | 0.4% | Sep 24, 2024 | The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2024-38269 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel ... |
| CVE-2024-38268 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG882... |
| CVE-2024-38267 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG88... |
| CVE-2024-38266 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG... |
| CVE-2024-7024 | CRITICAL | 9.6 | 0.3% | Sep 23, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perf... |
| CVE-2024-7023 | HIGH | 8.8 | 0.4% | Sep 23, 2024 | Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform priv... |
| CVE-2024-7022 | MEDIUM | 4.3 | 0.3% | Sep 23, 2024 | Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memor... |
| CVE-2024-7020 | MEDIUM | 4.3 | 0.3% | Sep 23, 2024 | Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI... |
| CVE-2024-7019 | MEDIUM | 4.3 | 0.3% | Sep 23, 2024 | Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a use... |
| CVE-2024-7018 | HIGH | 7.8 | 0.2% | Sep 23, 2024 | Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit hea... |
| CVE-2024-8770 | MEDIUM | 6.1 | 0.3% | Sep 23, 2024 | A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server... |
| CVE-2024-8263 | LOW | 2.7 | 0.4% | Sep 23, 2024 | An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PA... |
| CVE-2024-42861 | HIGH | 7.5 | 1.5% | Sep 23, 2024 | An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted... |
| CVE-2024-47222 | CRITICAL | 9.8 | 0.5% | Sep 23, 2024 | New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from exte... |
| CVE-2024-46639 | HIGH | 7.6 | 0.5% | Sep 23, 2024 | A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML... |
| CVE-2024-44540 | MEDIUM | 6.6 | 0.2% | Sep 23, 2024 | Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command s... |
| CVE-2024-43201 | MEDIUM | 5.9 | 0.4% | Sep 23, 2024 | The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now