2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12045 | MEDIUM | 4.8 | 0.2% | Jan 8, 2025 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-8002 | MEDIUM | 6.9 | 0.4% | Jan 8, 2025 | A vulnerability has been found in VIWIS LMS 9.11 and classified as problematic. Affected by this vulnerability is an unk... |
| CVE-2024-12852 | MEDIUM | 5.4 | 0.3% | Jan 8, 2025 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' p... |
| CVE-2024-12851 | MEDIUM | 5.4 | 0.3% | Jan 8, 2025 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for... |
| CVE-2024-12584 | MEDIUM | 6.5 | 0.3% | Jan 8, 2025 | The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure... |
| CVE-2024-12585 | MEDIUM | 6.1 | 0.6% | Jan 8, 2025 | The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in th... |
| CVE-2024-10585 | MEDIUM | 5.3 | 0.6% | Jan 8, 2025 | The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 ... |
| CVE-2024-10151 | MEDIUM | 5.4 | 0.3% | Jan 8, 2025 | The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2024-54731 | MEDIUM | 4 | 0.2% | Jan 8, 2025 | cpdf through 2.8 allows stack consumption via a crafted PDF document. |
| CVE-2024-12205 | MEDIUM | 5.4 | 0.3% | Jan 8, 2025 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slide... |
| CVE-2024-12030 | MEDIUM | 6.5 | 0.5% | Jan 8, 2025 | The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'key' attribute o... |
| CVE-2024-11271 | MEDIUM | 4.3 | 0.4% | Jan 8, 2025 | The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing ... |
| CVE-2024-56456 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu... |
| CVE-2024-56455 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu... |
| CVE-2024-56454 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu... |
| CVE-2024-56453 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu... |
| CVE-2024-56452 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successfu... |
| CVE-2024-56451 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this... |
| CVE-2024-56450 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may a... |
| CVE-2024-12713 | MEDIUM | 5.3 | 0.3% | Jan 8, 2025 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in a... |
| CVE-2024-12521 | MEDIUM | 6.4 | 0.3% | Jan 8, 2025 | The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti-embed-g... |
| CVE-2024-12112 | MEDIUM | 6.4 | 0.2% | Jan 8, 2025 | The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder ... |
| CVE-2024-11916 | MEDIUM | 5.4 | 0.2% | Jan 8, 2025 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and ret... |
| CVE-2024-56445 | MEDIUM | 5.3 | 0.3% | Jan 8, 2025 | Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulner... |
| CVE-2024-56441 | MEDIUM | 5.9 | 0.1% | Jan 8, 2025 | Race condition vulnerability in the Bastet module Impact: Successful exploitation of this vulnerability may affect servi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now