2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12448 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Posts and Products Views for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2024-12447 | MEDIUM | 4.3 | 0.3% | Dec 14, 2024 | The Get Post Content Shortcode plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up... |
| CVE-2024-12411 | MEDIUM | 6.1 | 0.3% | Dec 14, 2024 | The WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More plugin for WordPress is vulnerable to Store... |
| CVE-2024-11894 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The The Permalinker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'permalink' short... |
| CVE-2024-11889 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-... |
| CVE-2024-11888 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The IDer Login for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ider_lo... |
| CVE-2024-11884 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Wp photo text slider 50 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-photo... |
| CVE-2024-11883 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Connatix Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cnx_script_... |
| CVE-2024-11877 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Cricket Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cricket_score... |
| CVE-2024-11876 | MEDIUM | 6.4 | 0.2% | Dec 14, 2024 | The Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site plugin for WordPress is vulnerable t... |
| CVE-2024-11873 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The glomex oEmbed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glomex_integration... |
| CVE-2024-11869 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Buk for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buk' shortcode... |
| CVE-2024-11867 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Companion Portfolio – Responsive Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-11865 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Tabs Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 d... |
| CVE-2024-11855 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-11770 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The Post Carousel & Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-cs' ... |
| CVE-2024-11763 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The Plezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'plezi' shortcode in all ve... |
| CVE-2024-11759 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Bukza plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bukza' shortcode in all ve... |
| CVE-2024-11755 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The IMS Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown post settings in a... |
| CVE-2024-11751 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The TCBD Popover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd-popover-image ... |
| CVE-2024-11462 | MEDIUM | 6.1 | 0.4% | Dec 14, 2024 | The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filesta... |
| CVE-2024-11095 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Visualmodo Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads ... |
| CVE-2024-12553 | MEDIUM | 6.5 | 0.6% | Dec 13, 2024 | GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote atta... |
| CVE-2024-55890 | MEDIUM | 6.9 | 1.1% | Dec 13, 2024 | D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnera... |
| CVE-2024-9945 | MEDIUM | 5.3 | 0.3% | Dec 13, 2024 | An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now