2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7246 | MEDIUM | 5.3 | 0.2% | Aug 6, 2024 | It's possible for a gRPC client communicating with a HTTP/2 proxy to poison the HPACK table between the proxy and the ba... |
| CVE-2024-33981 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacke... |
| CVE-2024-33980 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacke... |
| CVE-2024-33979 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacke... |
| CVE-2024-33978 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially... |
| CVE-2024-33977 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially... |
| CVE-2024-33976 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulne... |
| CVE-2024-33975 | MEDIUM | 6.1 | 0.2% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulne... |
| CVE-2024-33959 | HIGH | 7.5 | 0.4% | Aug 6, 2024 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could explo... |
| CVE-2024-33958 | HIGH | 7.5 | 0.4% | Aug 6, 2024 | SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by s... |
| CVE-2024-33957 | HIGH | 7.5 | 0.4% | Aug 6, 2024 | SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by s... |
| CVE-2024-41995 | HIGH | 7.5 | 0.5% | Aug 6, 2024 | Initialization of a resource with an insecure default vulnerability exists in JavaTM Platform Ver.12.89 and earlier. If ... |
| CVE-2024-7084 | MEDIUM | 4.8 | 0.4% | Aug 6, 2024 | The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow user... |
| CVE-2024-7082 | MEDIUM | 6.1 | 0.4% | Aug 6, 2024 | The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allo... |
| CVE-2024-7055 | HIGH | 8.8 | 1.1% | Aug 6, 2024 | A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decod... |
| CVE-2024-6766 | MEDIUM | 5.4 | 0.3% | Aug 6, 2024 | The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes ... |
| CVE-2024-6651 | MEDIUM | 6.1 | 15.8% | Aug 6, 2024 | The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it b... |
| CVE-2024-6203 | HIGH | 8.1 | 0.4% | Aug 6, 2024 | HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links ... |
| CVE-2024-6202 | CRITICAL | 9.8 | 0.5% | Aug 6, 2024 | HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML in... |
| CVE-2024-6201 | MEDIUM | 5.3 | 0.3% | Aug 6, 2024 | HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate em... |
| CVE-2024-6200 | MEDIUM | 5.4 | 0.3% | Aug 6, 2024 | HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScri... |
| CVE-2024-5709 | HIGH | 8.8 | 1.0% | Aug 6, 2024 | The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu... |
| CVE-2024-5708 | MEDIUM | 5.4 | 0.2% | Aug 6, 2024 | The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter ... |
| CVE-2024-7506 | HIGH | 8.8 | 0.7% | Aug 6, 2024 | A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by t... |
| CVE-2024-39817 | MEDIUM | 6.5 | 0.4% | Aug 6, 2024 | Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now