2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12218 | MEDIUM | 6.1 | 0.2% | Jan 9, 2025 | The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in a... |
| CVE-2024-12206 | MEDIUM | 4.3 | 0.2% | Jan 9, 2025 | The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers... |
| CVE-2024-12122 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions ... |
| CVE-2024-12067 | MEDIUM | 6.5 | 0.5% | Jan 9, 2025 | The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injecti... |
| CVE-2024-11929 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp... |
| CVE-2024-11907 | MEDIUM | 6.4 | 0.4% | Jan 9, 2025 | The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_ifram... |
| CVE-2024-11815 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via... |
| CVE-2024-11686 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts... |
| CVE-2024-11328 | MEDIUM | 6.1 | 0.5% | Jan 9, 2025 | The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use ... |
| CVE-2024-13153 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widg... |
| CVE-2024-43662 | MEDIUM | 5.3 | 0.6% | Jan 9, 2025 | The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectiv... |
| CVE-2024-12806 | MEDIUM | 4.9 | 0.6% | Jan 9, 2025 | A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an ar... |
| CVE-2024-13041 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 pr... |
| CVE-2024-6324 | MEDIUM | 4.3 | 0.7% | Jan 9, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 pr... |
| CVE-2024-12736 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back... |
| CVE-2024-12731 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-12717 | MEDIUM | 4.8 | 0.4% | Jan 9, 2025 | The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow... |
| CVE-2024-12715 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it b... |
| CVE-2024-12714 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-10815 | MEDIUM | 4.2 | 0.3% | Jan 9, 2025 | The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it ... |
| CVE-2024-56827 | MEDIUM | 5.6 | 0.2% | Jan 9, 2025 | A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are spe... |
| CVE-2024-56826 | MEDIUM | 5.6 | 0.3% | Jan 9, 2025 | A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are spe... |
| CVE-2024-13213 | MEDIUM | 5.4 | 0.4% | Jan 9, 2025 | A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of ... |
| CVE-2024-13209 | MEDIUM | 5.4 | 0.4% | Jan 9, 2025 | A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function o... |
| CVE-2024-13205 | MEDIUM | 5.4 | 0.5% | Jan 9, 2025 | A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been rated as problematic. Affected by this issue... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now