2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54266 | MEDIUM | 6.1 | 0.4% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle Image... |
| CVE-2024-54259 | MEDIUM | 6.5 | 0.7% | Dec 13, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DELUCKS DELUCKS SEO delu... |
| CVE-2024-54252 | MEDIUM | 6.3 | 0.4% | Dec 13, 2024 | Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly C... |
| CVE-2024-54250 | MEDIUM | 6.5 | 0.4% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prodigycommerce Pr... |
| CVE-2024-54246 | MEDIUM | 6.5 | 0.4% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 FAQs faqs... |
| CVE-2024-54245 | MEDIUM | 6.5 | 0.4% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Clients c... |
| CVE-2024-54244 | MEDIUM | 6.5 | 0.4% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Easy Repl... |
| CVE-2024-54243 | MEDIUM | 6.5 | 0.4% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Echoza ec... |
| CVE-2024-54242 | MEDIUM | 6.5 | 0.3% | Dec 13, 2024 | Missing Authorization vulnerability in appsbd Simple Notification simple-notification allows Exploiting Incorrectly Conf... |
| CVE-2024-54241 | MEDIUM | 6.5 | 0.3% | Dec 13, 2024 | Missing Authorization vulnerability in Appsbd Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notific... |
| CVE-2024-47984 | MEDIUM | 6.5 | 0.5% | Dec 13, 2024 | Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability. A User with Remote access could p... |
| CVE-2024-24902 | MEDIUM | 5.5 | 0.2% | Dec 13, 2024 | Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local a... |
| CVE-2024-48008 | MEDIUM | 6.5 | 0.6% | Dec 13, 2024 | Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote att... |
| CVE-2024-9608 | MEDIUM | 6.1 | 0.3% | Dec 13, 2024 | The MyParcel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou... |
| CVE-2024-11827 | MEDIUM | 6.4 | 0.3% | Dec 13, 2024 | The Out of the Block: OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's o... |
| CVE-2024-11012 | MEDIUM | 6.3 | 0.5% | Dec 13, 2024 | The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via... |
| CVE-2024-12465 | MEDIUM | 6.4 | 0.3% | Dec 13, 2024 | The Property Hive Stamp Duty Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-12421 | MEDIUM | 6.5 | 0.5% | Dec 13, 2024 | The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-12420 | MEDIUM | 6.5 | 0.4% | Dec 13, 2024 | The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode exec... |
| CVE-2024-12417 | MEDIUM | 6.5 | 0.5% | Dec 13, 2024 | The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to,... |
| CVE-2024-12414 | MEDIUM | 4.3 | 0.2% | Dec 13, 2024 | The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-12309 | MEDIUM | 5.3 | 0.3% | Dec 13, 2024 | The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Referen... |
| CVE-2024-12042 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-11911 | MEDIUM | 4.3 | 0.3% | Dec 13, 2024 | The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability c... |
| CVE-2024-11910 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search blo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now