2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45847 | HIGH | 8.8 | 0.9% | Sep 12, 2024 | An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one ... |
| CVE-2024-45846 | HIGH | 8.8 | 2.1% | Sep 12, 2024 | An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the ... |
| CVE-2024-3306 | HIGH | 7.5 | 0.4% | Sep 12, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrec... |
| CVE-2024-3305 | HIGH | 7.5 | 0.4% | Sep 12, 2024 | Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub all... |
| CVE-2024-27321 | HIGH | 7.8 | 0.3% | Sep 12, 2024 | An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of ... |
| CVE-2024-27320 | HIGH | 7.8 | 0.3% | Sep 12, 2024 | An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of ... |
| CVE-2024-8750 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve sess... |
| CVE-2024-8749 | HIGH | 7.5 | 0.4% | Sep 12, 2024 | SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially craf... |
| CVE-2024-8622 | MEDIUM | 6.1 | 0.4% | Sep 12, 2024 | The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_jav... |
| CVE-2024-8529 | HIGH | 7.5 | 11.8% | Sep 12, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter o... |
| CVE-2024-8522 | HIGH | 7.5 | 61.4% | Sep 12, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parame... |
| CVE-2024-2010 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows ... |
| CVE-2024-8056 | MEDIUM | 6.1 | 0.3% | Sep 12, 2024 | The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputt... |
| CVE-2024-8054 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation... |
| CVE-2024-7862 | MEDIUM | 6.5 | 0.2% | Sep 12, 2024 | The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its... |
| CVE-2024-7861 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisa... |
| CVE-2024-7860 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitis... |
| CVE-2024-7859 | MEDIUM | 6.5 | 0.2% | Sep 12, 2024 | The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could... |
| CVE-2024-7822 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well... |
| CVE-2024-7820 | MEDIUM | 6.5 | 0.2% | Sep 12, 2024 | The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could ... |
| CVE-2024-7818 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisati... |
| CVE-2024-7817 | MEDIUM | 6.5 | 0.2% | Sep 12, 2024 | The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attack... |
| CVE-2024-7816 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well... |
| CVE-2024-7766 | HIGH | 7.2 | 0.6% | Sep 12, 2024 | The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL stateme... |
| CVE-2024-6887 | MEDIUM | 4.8 | 0.4% | Sep 12, 2024 | The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Give... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now