2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12260 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page'... |
| CVE-2024-12258 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ... |
| CVE-2024-11914 | MEDIUM | 6.4 | 0.4% | Dec 12, 2024 | The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-11901 | MEDIUM | 6.4 | 0.5% | Dec 12, 2024 | The PowerBI Embed Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MO_API_POW... |
| CVE-2024-11683 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The Newsletter Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'token_type' p... |
| CVE-2024-11442 | MEDIUM | 6.4 | 0.4% | Dec 12, 2024 | The Horizontal scroll image slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2024-11433 | MEDIUM | 6.4 | 0.4% | Dec 12, 2024 | The Surbma | SalesAutopilot Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2024-11430 | MEDIUM | 6.5 | 0.5% | Dec 12, 2024 | The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' short... |
| CVE-2024-11427 | MEDIUM | 6.4 | 0.4% | Dec 12, 2024 | The Catch Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catch-popup' shortco... |
| CVE-2024-11419 | MEDIUM | 6.1 | 0.2% | Dec 12, 2024 | The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2024-11417 | MEDIUM | 6.1 | 0.2% | Dec 12, 2024 | The dejure.org Vernetzungsfunktion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2024-11413 | MEDIUM | 6.4 | 0.4% | Dec 12, 2024 | The HostFact bestelformulier integratie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-11279 | MEDIUM | 6.1 | 0.5% | Dec 12, 2024 | The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad... |
| CVE-2024-55659 | MEDIUM | 5.4 | 0.4% | Dec 12, 2024 | SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is... |
| CVE-2024-55652 | MEDIUM | 6.5 | 0.7% | Dec 12, 2024 | PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an atta... |
| CVE-2024-54531 | MEDIUM | 5.5 | 0.2% | Dec 12, 2024 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. An app may be able to ... |
| CVE-2024-54527 | MEDIUM | 5.5 | 0.3% | Dec 12, 2024 | This issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macO... |
| CVE-2024-54526 | MEDIUM | 5.5 | 3.2% | Dec 12, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS... |
| CVE-2024-54524 | MEDIUM | 5.5 | 0.2% | Dec 12, 2024 | A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2. A malicious app may ... |
| CVE-2024-54513 | MEDIUM | 5.5 | 0.3% | Dec 12, 2024 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS S... |
| CVE-2024-54510 | MEDIUM | 5.1 | 0.2% | Dec 12, 2024 | A race condition was addressed with improved locking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, ma... |
| CVE-2024-54504 | MEDIUM | 5.5 | 0.2% | Dec 12, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia... |
| CVE-2024-54503 | MEDIUM | 4.2 | 0.4% | Dec 12, 2024 | An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.2 and i... |
| CVE-2024-54502 | MEDIUM | 6.5 | 14.5% | Dec 12, 2024 | The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.... |
| CVE-2024-54501 | MEDIUM | 5.5 | 0.3% | Dec 12, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now