2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11358 | MEDIUM | 5.5 | 0.1% | Dec 16, 2024 | Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with... |
| CVE-2024-56003 | MEDIUM | 4.3 | 0.3% | Dec 16, 2024 | Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer caldera-smtp-mailer.This issue affects Caldera S... |
| CVE-2024-55999 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in Marco Giannini XML Multilanguage Sitemap Generator xml-multilanguage-sitemap-gene... |
| CVE-2024-54357 | MEDIUM | 4.3 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <=... |
| CVE-2024-54348 | MEDIUM | 6.5 | 0.2% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yaycommerce Brand ... |
| CVE-2024-12654 | MEDIUM | 5.5 | 0.3% | Dec 16, 2024 | A vulnerability classified as problematic was found in FabulaTech USB over Network 6.0.6.1. Affected by this vulnerabili... |
| CVE-2024-12653 | MEDIUM | 5.5 | 0.4% | Dec 16, 2024 | A vulnerability classified as problematic has been found in FabulaTech USB over Network 6.0.6.1. Affected is the functio... |
| CVE-2024-56011 | MEDIUM | 6.5 | 0.3% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilja Zaglov Respon... |
| CVE-2024-56009 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality... |
| CVE-2024-56007 | MEDIUM | 4.3 | 0.3% | Dec 16, 2024 | Missing Authorization vulnerability in leader codes Leader leader allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2024-56005 | MEDIUM | 6.5 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Posti Posti Shipping posti-shipping allows Cross Site Request Forgery... |
| CVE-2024-56004 | MEDIUM | 5.4 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in awfowler Easy Site Importer easy-site-importer allows Exploiting Incorrectly Conf... |
| CVE-2024-56001 | MEDIUM | 6.5 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in ksher thailand Ksher ksher-payment allows Exploiting Incorrectly Configured Acces... |
| CVE-2024-55998 | MEDIUM | 5.4 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in Eric Sloan Popup Surveys & Polls for WordPress (Mare.io) popup-surveys allows Exp... |
| CVE-2024-55996 | MEDIUM | 6.1 | 0.3% | Dec 16, 2024 | Missing Authorization vulnerability in dreamfox Dreamfox Media Payment gateway per Product for Woocommerce woocommerce-p... |
| CVE-2024-55994 | MEDIUM | 4.3 | 0.5% | Dec 16, 2024 | Missing Authorization vulnerability in sohu 畅言评论系统 changyan allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2024-55993 | MEDIUM | 5.3 | 0.5% | Dec 16, 2024 | Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Con... |
| CVE-2024-55992 | MEDIUM | 5.4 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in Open Tools WooCommerce Basic Ordernumbers woocommerce-basic-ordernumbers allows E... |
| CVE-2024-54443 | MEDIUM | 6.5 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginsCafe Advanc... |
| CVE-2024-54442 | MEDIUM | 5.9 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cortesfrau Better ... |
| CVE-2024-54441 | MEDIUM | 6.5 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Meini Utech World ... |
| CVE-2024-54430 | MEDIUM | 5.4 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Europe Ecologie Les Verts EELV Newsletter eelv-newsletter allows Cros... |
| CVE-2024-54419 | MEDIUM | 5.4 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in chenyenming Ui Slider Filter By Price ui-slider-filter-by-price allow... |
| CVE-2024-54418 | MEDIUM | 5.4 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Diversified Technology Corp. DTC Documents dtc-documents allows Cross... |
| CVE-2024-54417 | MEDIUM | 5.3 | 0.5% | Dec 16, 2024 | Missing Authorization vulnerability in pixelgrade PixProof pixproof allows Accessing Functionality Not Properly Constrai... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now