2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36831 | MEDIUM | 5.3 | 0.7% | Dec 17, 2024 | A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02... |
| CVE-2024-9819 | MEDIUM | 6.5 | 0.4% | Dec 17, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse.... |
| CVE-2024-54677 | MEDIUM | 5.3 | 1.9% | Dec 17, 2024 | Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to den... |
| CVE-2024-10356 | MEDIUM | 4.3 | 0.4% | Dec 17, 2024 | The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi... |
| CVE-2024-8475 | MEDIUM | 6.5 | 0.4% | Dec 17, 2024 | Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulati... |
| CVE-2024-8429 | MEDIUM | 4.3 | 0.4% | Dec 17, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows ... |
| CVE-2024-52542 | MEDIUM | 5.5 | 0.2% | Dec 17, 2024 | Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with... |
| CVE-2024-12601 | MEDIUM | 5.3 | 0.5% | Dec 17, 2024 | The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including,... |
| CVE-2024-12395 | MEDIUM | 6.1 | 0.5% | Dec 17, 2024 | The WooCommerce Additional Fees On Checkout (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-11280 | MEDIUM | 5.3 | 0.4% | Dec 17, 2024 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u... |
| CVE-2024-12469 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2024-12127 | MEDIUM | 6.1 | 0.3% | Dec 17, 2024 | The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vu... |
| CVE-2024-12024 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-11294 | MEDIUM | 5.3 | 0.5% | Dec 17, 2024 | The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-12220 | MEDIUM | 6.1 | 0.2% | Dec 17, 2024 | The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2024-12219 | MEDIUM | 6.1 | 0.2% | Dec 17, 2024 | The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-55864 | MEDIUM | 4.8 | 0.3% | Dec 17, 2024 | Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious... |
| CVE-2024-12239 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navig... |
| CVE-2024-11906 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The TPG Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpg_get_posts' sho... |
| CVE-2024-11905 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animatedcounte... |
| CVE-2024-11902 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations... |
| CVE-2024-11900 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-55452 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of ... |
| CVE-2024-55451 | MEDIUM | 4.8 | 0.3% | Dec 16, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in U... |
| CVE-2024-35230 | MEDIUM | 5.3 | 0.7% | Dec 16, 2024 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now