2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11841 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes be... |
| CVE-2024-8650 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6... |
| CVE-2024-8116 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.... |
| CVE-2024-8798 | MEDIUM | 6.5 | 0.4% | Dec 16, 2024 | No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.... |
| CVE-2024-56074 | MEDIUM | 5.5 | 0.3% | Dec 15, 2024 | gitingest before 9996a06 mishandles symbolic links that point outside of the base directory. |
| CVE-2024-11720 | MEDIUM | 6.1 | 0.3% | Dec 14, 2024 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms ... |
| CVE-2024-12628 | MEDIUM | 4.4 | 0.4% | Dec 14, 2024 | The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' paramete... |
| CVE-2024-12446 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Post to Pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gmptp_single_post' s... |
| CVE-2024-11714 | MEDIUM | 4.9 | 0.5% | Dec 14, 2024 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to... |
| CVE-2024-11713 | MEDIUM | 4.9 | 0.5% | Dec 14, 2024 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to... |
| CVE-2024-11712 | MEDIUM | 5.3 | 0.4% | Dec 14, 2024 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to... |
| CVE-2024-11710 | MEDIUM | 4.9 | 0.5% | Dec 14, 2024 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to... |
| CVE-2024-12501 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Simple Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all ... |
| CVE-2024-12474 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2024-12459 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The Ganohrs Toggle Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggle'... |
| CVE-2024-12422 | MEDIUM | 6.1 | 0.4% | Dec 14, 2024 | The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramet... |
| CVE-2024-11752 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Eveeno plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eveeno' shortcode in all ... |
| CVE-2024-10690 | MEDIUM | 4.3 | 0.3% | Dec 14, 2024 | The Shortcodes for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu... |
| CVE-2024-10646 | MEDIUM | 6.1 | 0.3% | Dec 14, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-12578 | MEDIUM | 5.3 | 0.5% | Dec 14, 2024 | The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to... |
| CVE-2024-12555 | MEDIUM | 6.1 | 0.2% | Dec 14, 2024 | The SIP Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2024-12523 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The States Map US plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'states_map' shortc... |
| CVE-2024-12517 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The WooCommerce Cart Count Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-12502 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-... |
| CVE-2024-12458 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now