2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11883 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Connatix Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cnx_script_... |
| CVE-2024-11877 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Cricket Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cricket_score... |
| CVE-2024-11876 | MEDIUM | 6.4 | 0.2% | Dec 14, 2024 | The Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site plugin for WordPress is vulnerable t... |
| CVE-2024-11873 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The glomex oEmbed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glomex_integration... |
| CVE-2024-11869 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Buk for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buk' shortcode... |
| CVE-2024-11867 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Companion Portfolio – Responsive Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-11865 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Tabs Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 d... |
| CVE-2024-11855 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-11770 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The Post Carousel & Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-cs' ... |
| CVE-2024-11763 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The Plezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'plezi' shortcode in all ve... |
| CVE-2024-11759 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Bukza plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bukza' shortcode in all ve... |
| CVE-2024-11755 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The IMS Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown post settings in a... |
| CVE-2024-11751 | MEDIUM | 6.4 | 0.4% | Dec 14, 2024 | The TCBD Popover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd-popover-image ... |
| CVE-2024-11462 | MEDIUM | 6.1 | 0.4% | Dec 14, 2024 | The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filesta... |
| CVE-2024-11095 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Visualmodo Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads ... |
| CVE-2024-12553 | MEDIUM | 6.5 | 0.6% | Dec 13, 2024 | GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote atta... |
| CVE-2024-55890 | MEDIUM | 6.9 | 1.1% | Dec 13, 2024 | D-Tale is a visualizer for pandas data structures. Prior to version 3.16.1, users hosting D-Tale publicly can be vulnera... |
| CVE-2024-9945 | MEDIUM | 5.3 | 0.3% | Dec 13, 2024 | An information-disclosure vulnerability exists in Fortra's GoAnywhere MFT application prior to version 7.7.0 that allows... |
| CVE-2024-54349 | MEDIUM | 6.5 | 0.3% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mashiurz Plain Pos... |
| CVE-2024-54346 | MEDIUM | 6.5 | 0.3% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 Barte... |
| CVE-2024-54345 | MEDIUM | 6.5 | 0.3% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 Bicyc... |
| CVE-2024-54338 | MEDIUM | 6.5 | 0.3% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in christer_f Hello E... |
| CVE-2024-54334 | MEDIUM | 6.5 | 0.3% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zeshanb Quran Phra... |
| CVE-2024-54326 | MEDIUM | 6.5 | 0.5% | Dec 13, 2024 | Missing Authorization vulnerability in Eyal Fitoussi GEO my WordPress geo-my-wp allows Exploiting Incorrectly Configured... |
| CVE-2024-54323 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Config... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now