2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54356 | MEDIUM | 5.4 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita mee... |
| CVE-2024-54354 | MEDIUM | 6.5 | 0.3% | Dec 16, 2024 | Missing Authorization vulnerability in beat.k Termin-Kalender termin-kalender allows Stored XSS.This issue affects Termi... |
| CVE-2024-37251 | MEDIUM | 4.3 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced... |
| CVE-2024-12092 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE... |
| CVE-2024-12091 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER... |
| CVE-2024-12090 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE... |
| CVE-2024-12089 | MEDIUM | 5.4 | 0.4% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER... |
| CVE-2024-12362 | MEDIUM | 5.3 | 0.5% | Dec 16, 2024 | A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function ... |
| CVE-2024-54682 | MEDIUM | 4.9 | 0.4% | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size fo... |
| CVE-2024-54083 | MEDIUM | 6.5 | 0.6% | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the ... |
| CVE-2024-48872 | MEDIUM | 4.8 | 0.2% | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrent... |
| CVE-2024-9679 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | A Hardcoded Cryptographic key vulnerability existed in DLP Extension 11.11.1.3 which allowed the decryption of previousl... |
| CVE-2024-9678 | MEDIUM | 4.9 | 0.7% | Dec 16, 2024 | An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arb... |
| CVE-2024-12645 | MEDIUM | 6.5 | 0.3% | Dec 16, 2024 | The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local w... |
| CVE-2024-5333 | MEDIUM | 5.3 | 1.1% | Dec 16, 2024 | The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticat... |
| CVE-2024-56112 | MEDIUM | 6.1 | 0.2% | Dec 16, 2024 | CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php. |
| CVE-2024-56087 | MEDIUM | 5.9 | 0.3% | Dec 16, 2024 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template... |
| CVE-2024-56085 | MEDIUM | 5.9 | 0.3% | Dec 16, 2024 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template... |
| CVE-2024-11841 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes be... |
| CVE-2024-8650 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6... |
| CVE-2024-8116 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.... |
| CVE-2024-8798 | MEDIUM | 6.5 | 0.4% | Dec 16, 2024 | No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.... |
| CVE-2024-56074 | MEDIUM | 5.5 | 0.3% | Dec 15, 2024 | gitingest before 9996a06 mishandles symbolic links that point outside of the base directory. |
| CVE-2024-11720 | MEDIUM | 6.1 | 0.3% | Dec 14, 2024 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms ... |
| CVE-2024-12628 | MEDIUM | 4.4 | 0.4% | Dec 14, 2024 | The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' paramete... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now