2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54408 | MEDIUM | 6.5 | 0.4% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in codehandling Youtube Video Grid youmax-channel-embeds-for-youtube-bus... |
| CVE-2024-54402 | MEDIUM | 4.3 | 0.6% | Dec 16, 2024 | Missing Authorization vulnerability in Mohamed Abd Elhalim Arabic Webfonts arabic-webfonts allows Exploiting Incorrectly... |
| CVE-2024-54396 | MEDIUM | 4.3 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in elmervillanueva Bet sport Free bet-sport-free allows Cross Site Reque... |
| CVE-2024-54384 | MEDIUM | 4.3 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in Anh Tran Falcon – WordPress Optimizations & Tweaks falcon allows Exploiting Incor... |
| CVE-2024-54382 | MEDIUM | 4.9 | 2.2% | Dec 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in boldthemes Bold Page Bui... |
| CVE-2024-54366 | MEDIUM | 5.3 | 0.6% | Dec 16, 2024 | Generation of Error Message Containing Sensitive Information vulnerability in videogallery Vimeography vimeography allow... |
| CVE-2024-54360 | MEDIUM | 6.5 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in premila Gutensee g... |
| CVE-2024-54356 | MEDIUM | 5.4 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita mee... |
| CVE-2024-54354 | MEDIUM | 6.5 | 0.3% | Dec 16, 2024 | Missing Authorization vulnerability in beat.k Termin-Kalender termin-kalender allows Stored XSS.This issue affects Termi... |
| CVE-2024-37251 | MEDIUM | 4.3 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced... |
| CVE-2024-12092 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE... |
| CVE-2024-12091 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER... |
| CVE-2024-12090 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE... |
| CVE-2024-12089 | MEDIUM | 5.4 | 0.4% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER... |
| CVE-2024-12362 | MEDIUM | 5.3 | 0.5% | Dec 16, 2024 | A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function ... |
| CVE-2024-54682 | MEDIUM | 4.9 | 0.4% | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size fo... |
| CVE-2024-54083 | MEDIUM | 6.5 | 0.6% | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the ... |
| CVE-2024-48872 | MEDIUM | 4.8 | 0.2% | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrent... |
| CVE-2024-9679 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | A Hardcoded Cryptographic key vulnerability existed in DLP Extension 11.11.1.3 which allowed the decryption of previousl... |
| CVE-2024-9678 | MEDIUM | 4.9 | 0.7% | Dec 16, 2024 | An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arb... |
| CVE-2024-12645 | MEDIUM | 6.5 | 0.3% | Dec 16, 2024 | The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local w... |
| CVE-2024-5333 | MEDIUM | 5.3 | 1.1% | Dec 16, 2024 | The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticat... |
| CVE-2024-56112 | MEDIUM | 6.1 | 0.2% | Dec 16, 2024 | CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php. |
| CVE-2024-56087 | MEDIUM | 5.9 | 0.3% | Dec 16, 2024 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template... |
| CVE-2024-56085 | MEDIUM | 5.9 | 0.3% | Dec 16, 2024 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now