2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43265 | LOW | 3.5 | 0.2% | Aug 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1. |
| CVE-2024-43264 | HIGH | 7.5 | 0.4% | Aug 26, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in mischiefmarmot Create by Mediavine mediavine-create.T... |
| CVE-2024-43259 | HIGH | 7.5 | 0.4% | Aug 26, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in WebFactory Order Export for WooCommerce order-export-... |
| CVE-2024-43258 | HIGH | 7.5 | 0.4% | Aug 26, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Store Locator Plus.This issue affects Store ... |
| CVE-2024-43257 | MEDIUM | 6.5 | 0.4% | Aug 26, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Nouthemes Leopard - WordPress offload media.... |
| CVE-2024-43255 | MEDIUM | 6.1 | 0.2% | Aug 26, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTa... |
| CVE-2024-43251 | MEDIUM | 6.5 | 0.4% | Aug 26, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bit Apps Bit Form Pro.This issue affects Bit... |
| CVE-2024-43230 | HIGH | 7.5 | 0.4% | Aug 26, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue af... |
| CVE-2024-43214 | MEDIUM | 5.3 | 0.3% | Aug 26, 2024 | Missing Authorization vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2. |
| CVE-2024-43117 | HIGH | 8.8 | 0.2% | Aug 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird... |
| CVE-2024-43116 | HIGH | 8.8 | 0.2% | Aug 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: fr... |
| CVE-2024-39657 | HIGH | 8.8 | 0.2% | Aug 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for Wo... |
| CVE-2024-39645 | HIGH | 8.8 | 0.2% | Aug 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.... |
| CVE-2024-39641 | HIGH | 8.8 | 0.2% | Aug 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through ... |
| CVE-2024-39628 | HIGH | 8.8 | 0.2% | Aug 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This iss... |
| CVE-2024-8188 | — | — | — | Aug 26, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-8105 | MEDIUM | 6.4 | 0.2% | Aug 26, 2024 | A vulnerability exists in UEFI implementations that use a hard-coded software-based Platform Key (PK). An attacker in po... |
| CVE-2024-44797 | MEDIUM | 6.1 | 0.4% | Aug 26, 2024 | A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allo... |
| CVE-2024-44796 | MEDIUM | 6.1 | 0.5% | Aug 26, 2024 | A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows... |
| CVE-2024-44795 | MEDIUM | 6.1 | 0.3% | Aug 26, 2024 | A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attacke... |
| CVE-2024-44794 | MEDIUM | 6.1 | 0.3% | Aug 26, 2024 | A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf8... |
| CVE-2024-44793 | MEDIUM | 6.1 | 0.3% | Aug 26, 2024 | A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 a... |
| CVE-2024-42906 | MEDIUM | 6.1 | 0.3% | Aug 26, 2024 | TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a fil... |
| CVE-2024-28077 | HIGH | 7.5 | 0.4% | Aug 26, 2024 | A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the ext... |
| CVE-2024-43806 | MEDIUM | 6.5 | 0.5% | Aug 26, 2024 | Rustix is a set of safe Rust bindings to POSIX-ish APIs. When using `rustix::fs::Dir` using the `linux_raw` backend, it'... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now