2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12420 | MEDIUM | 6.5 | 0.4% | Dec 13, 2024 | The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode exec... |
| CVE-2024-12417 | MEDIUM | 6.5 | 0.5% | Dec 13, 2024 | The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to,... |
| CVE-2024-12414 | MEDIUM | 4.3 | 0.2% | Dec 13, 2024 | The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-12309 | MEDIUM | 5.3 | 0.3% | Dec 13, 2024 | The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Referen... |
| CVE-2024-12042 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-11911 | MEDIUM | 4.3 | 0.3% | Dec 13, 2024 | The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability c... |
| CVE-2024-11910 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search blo... |
| CVE-2024-11832 | MEDIUM | 5.4 | 0.2% | Dec 13, 2024 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cu... |
| CVE-2024-11754 | MEDIUM | 6.4 | 0.3% | Dec 13, 2024 | The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trafftbook... |
| CVE-2024-11275 | MEDIUM | 4.3 | 0.3% | Dec 13, 2024 | The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable... |
| CVE-2024-55918 | MEDIUM | 5.3 | 0.5% | Dec 13, 2024 | An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules... |
| CVE-2024-12581 | MEDIUM | 4.8 | 0.5% | Dec 13, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-10939 | MEDIUM | 4.8 | 0.3% | Dec 13, 2024 | The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which co... |
| CVE-2024-10678 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputt... |
| CVE-2024-12579 | MEDIUM | 5.3 | 0.3% | Dec 13, 2024 | The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to... |
| CVE-2024-12574 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | The SVG Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions... |
| CVE-2024-11809 | MEDIUM | 6.1 | 0.3% | Dec 13, 2024 | The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'img_src'... |
| CVE-2024-11767 | MEDIUM | 6.4 | 0.3% | Dec 13, 2024 | The NewsmanApp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'newsman_subscribe_wid... |
| CVE-2024-12572 | MEDIUM | 6.1 | 0.2% | Dec 13, 2024 | The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-12289 | MEDIUM | 5.9 | 0.4% | Dec 12, 2024 | Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initializati... |
| CVE-2024-55886 | MEDIUM | 6.9 | 0.3% | Dec 12, 2024 | OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes... |
| CVE-2024-55878 | MEDIUM | 6.8 | 0.4% | Dec 12, 2024 | SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to ve... |
| CVE-2024-55876 | MEDIUM | 5.4 | 0.6% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0,... |
| CVE-2024-49071 | MEDIUM | 6.5 | 1.1% | Dec 12, 2024 | Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender al... |
| CVE-2024-47238 | MEDIUM | 6.7 | 0.2% | Dec 12, 2024 | Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now