2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12031 | MEDIUM | 6.5 | 0.4% | Dec 24, 2024 | The Advanced Floating Content plugin for WordPress is vulnerable to SQL Injection via the 'floating_content_duplicate_po... |
| CVE-2024-12468 | MEDIUM | 6.1 | 0.4% | Dec 24, 2024 | The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepi... |
| CVE-2024-11896 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-12814 | MEDIUM | 6.4 | 0.4% | Dec 24, 2024 | The Loan Comparison plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'loancomparison' ... |
| CVE-2024-41887 | MEDIUM | 5.1 | 1.0% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can... |
| CVE-2024-41886 | MEDIUM | 6.9 | 0.6% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker cou... |
| CVE-2024-41885 | MEDIUM | 5.6 | 0.2% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. The seed string... |
| CVE-2024-41884 | MEDIUM | 6.9 | 0.8% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. If an attacker ... |
| CVE-2024-41883 | MEDIUM | 6.9 | 0.6% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR . An attacker... |
| CVE-2024-41882 | MEDIUM | 6.9 | 0.6% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can... |
| CVE-2024-12622 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w... |
| CVE-2024-12405 | MEDIUM | 6.1 | 0.3% | Dec 24, 2024 | The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in ... |
| CVE-2024-12210 | MEDIUM | 4.3 | 0.3% | Dec 24, 2024 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da... |
| CVE-2024-12100 | MEDIUM | 6.1 | 0.3% | Dec 24, 2024 | The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t... |
| CVE-2024-12096 | MEDIUM | 6.1 | 0.3% | Dec 24, 2024 | The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it b... |
| CVE-2024-12034 | MEDIUM | 5.3 | 0.3% | Dec 24, 2024 | The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, ... |
| CVE-2024-11885 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njte... |
| CVE-2024-12710 | MEDIUM | 6.1 | 0.3% | Dec 24, 2024 | The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versi... |
| CVE-2024-12617 | MEDIUM | 5.4 | 0.3% | Dec 24, 2024 | The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability c... |
| CVE-2024-12518 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' sho... |
| CVE-2024-12507 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' ... |
| CVE-2024-12266 | MEDIUM | 6.5 | 0.3% | Dec 24, 2024 | The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due... |
| CVE-2024-9427 | MEDIUM | 5.4 | 0.3% | Dec 24, 2024 | A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link ... |
| CVE-2024-56362 | MEDIUM | 5.5 | 0.1% | Dec 23, 2024 | Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext... |
| CVE-2024-53276 | MEDIUM | 6.3 | 0.5% | Dec 23, 2024 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now