2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12262 | MEDIUM | 6.1 | 0.4% | Dec 21, 2024 | The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all ver... |
| CVE-2024-11975 | MEDIUM | 6.1 | 0.4% | Dec 21, 2024 | The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th... |
| CVE-2024-11938 | MEDIUM | 6.4 | 0.3% | Dec 21, 2024 | The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Up... |
| CVE-2024-11682 | MEDIUM | 6.1 | 0.4% | Dec 21, 2024 | The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter i... |
| CVE-2024-11287 | MEDIUM | 6.1 | 0.3% | Dec 21, 2024 | The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit... |
| CVE-2024-11196 | MEDIUM | 6.4 | 0.4% | Dec 21, 2024 | The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mctagmap sho... |
| CVE-2024-11607 | MEDIUM | 6.1 | 0.2% | Dec 21, 2024 | The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisat... |
| CVE-2024-12846 | MEDIUM | 4.8 | 0.4% | Dec 21, 2024 | A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is... |
| CVE-2024-11811 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'platf... |
| CVE-2024-12845 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unkno... |
| CVE-2024-56359 | MEDIUM | 6.1 | 0.3% | Dec 20, 2024 | grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink c... |
| CVE-2024-56358 | MEDIUM | 6.1 | 0.3% | Dec 20, 2024 | grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have... |
| CVE-2024-56357 | MEDIUM | 6.1 | 0.3% | Dec 20, 2024 | grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could ha... |
| CVE-2024-40875 | MEDIUM | 5.9 | 0.3% | Dec 20, 2024 | There is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.52... |
| CVE-2024-12844 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.1. Affected is an unknown function of th... |
| CVE-2024-12843 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | A vulnerability was found in Emlog Pro up to 2.4.1. It has been rated as problematic. This issue affects some unknown pr... |
| CVE-2024-56331 | MEDIUM | 6.8 | 1.8% | Dec 20, 2024 | Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacke... |
| CVE-2024-55341 | MEDIUM | 4.7 | 0.4% | Dec 20, 2024 | A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaS... |
| CVE-2024-12842 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unkn... |
| CVE-2024-55342 | MEDIUM | 4.7 | 0.5% | Dec 20, 2024 | A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /m... |
| CVE-2024-12841 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part ... |
| CVE-2024-55471 | MEDIUM | 6.5 | 0.3% | Dec 20, 2024 | Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This all... |
| CVE-2024-55186 | MEDIUM | 4.3 | 0.3% | Dec 20, 2024 | An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to ... |
| CVE-2024-56355 | MEDIUM | 5.4 | 0.8% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS |
| CVE-2024-56354 | MEDIUM | 4.9 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now