2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31415 | HIGH | 8.1 | 0.1% | Sep 13, 2024 | The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes su... |
| CVE-2024-31414 | MEDIUM | 6.1 | 0.3% | Sep 13, 2024 | The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the inpu... |
| CVE-2024-6587 | HIGH | 7.5 | 36.9% | Sep 13, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows ... |
| CVE-2024-44798 | MEDIUM | 4.8 | 0.3% | Sep 13, 2024 | phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-det... |
| CVE-2024-44685 | MEDIUM | 5 | 0.3% | Sep 13, 2024 | Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information... |
| CVE-2024-42025 | HIGH | 7.8 | 0.8% | Sep 13, 2024 | A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (V... |
| CVE-2024-8747 | MEDIUM | 5.4 | 0.3% | Sep 13, 2024 | The Email Obfuscate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email-... |
| CVE-2024-8737 | MEDIUM | 6.1 | 0.4% | Sep 13, 2024 | The PDF Thumbnail Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q... |
| CVE-2024-8734 | MEDIUM | 6.1 | 0.3% | Sep 13, 2024 | The Lucas String Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer... |
| CVE-2024-8732 | MEDIUM | 6.1 | 0.4% | Sep 13, 2024 | The Roles & Capabilities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer... |
| CVE-2024-8731 | MEDIUM | 6.1 | 0.4% | Sep 13, 2024 | The Cron Jobs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho... |
| CVE-2024-8730 | MEDIUM | 6.1 | 0.4% | Sep 13, 2024 | The Exit Notifier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg w... |
| CVE-2024-8714 | MEDIUM | 6.1 | 0.4% | Sep 13, 2024 | The WordPress Affiliates Plugin — SliceWP Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin... |
| CVE-2024-8269 | MEDIUM | 6.5 | 0.4% | Sep 13, 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user r... |
| CVE-2024-8242 | HIGH | 8.8 | 0.8% | Sep 13, 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uplo... |
| CVE-2024-7423 | HIGH | 8.8 | 0.3% | Sep 13, 2024 | The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1.... |
| CVE-2024-6544 | MEDIUM | 5.3 | 0.4% | Sep 13, 2024 | The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, ... |
| CVE-2024-5884 | MEDIUM | 5.4 | 0.3% | Sep 13, 2024 | The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter in a... |
| CVE-2024-5870 | MEDIUM | 5.4 | 0.3% | Sep 13, 2024 | The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's... |
| CVE-2024-5869 | MEDIUM | 5.4 | 0.3% | Sep 13, 2024 | The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme... |
| CVE-2024-5867 | MEDIUM | 5.4 | 0.3% | Sep 13, 2024 | The Delicate theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter within the theme'... |
| CVE-2024-5789 | MEDIUM | 5.4 | 0.3% | Sep 13, 2024 | The Triton Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the them... |
| CVE-2024-46713 | HIGH | 7.8 | 0.3% | Sep 13, 2024 | In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reporte... |
| CVE-2024-46049 | CRITICAL | 9.8 | 0.6% | Sep 13, 2024 | Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function. |
| CVE-2024-46048 | CRITICAL | 9.8 | 10.5% | Sep 13, 2024 | Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now