2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13249 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framin... |
| CVE-2024-13248 | MEDIUM | 5.5 | 0.2% | Jan 9, 2025 | Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue af... |
| CVE-2024-13247 | MEDIUM | 4.8 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allo... |
| CVE-2024-13246 | MEDIUM | 5.3 | 0.3% | Jan 9, 2025 | Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framin... |
| CVE-2024-13245 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 ... |
| CVE-2024-13243 | MEDIUM | 6.5 | 0.3% | Jan 9, 2025 | Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delet... |
| CVE-2024-13238 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Typogrify a... |
| CVE-2024-13237 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity... |
| CVE-2024-43176 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should o... |
| CVE-2024-6155 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Ser... |
| CVE-2024-5769 | MEDIUM | 4.3 | 0.4% | Jan 9, 2025 | The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-12819 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortc... |
| CVE-2024-12621 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' ... |
| CVE-2024-12618 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2024-12616 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-12605 | MEDIUM | 4.3 | 0.2% | Jan 9, 2025 | The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch... |
| CVE-2024-12515 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID ... |
| CVE-2024-12514 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' short... |
| CVE-2024-12496 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissi... |
| CVE-2024-12493 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' sh... |
| CVE-2024-12491 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_se... |
| CVE-2024-12394 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all ... |
| CVE-2024-12285 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versi... |
| CVE-2024-12249 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2024-12222 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvs... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now