2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30129 | MEDIUM | 5.3 | 0.3% | Dec 6, 2024 | The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the ... |
| CVE-2024-42196 | MEDIUM | 5.5 | 0.1% | Dec 6, 2024 | HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP ... |
| CVE-2024-54213 | MEDIUM | 6.5 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zionbuilder ZionBu... |
| CVE-2024-54212 | MEDIUM | 5.4 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical ... |
| CVE-2024-54211 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderl... |
| CVE-2024-54210 | MEDIUM | 6.5 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codexshaper Advanc... |
| CVE-2024-54207 | MEDIUM | 5.9 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Marka WordPress... |
| CVE-2024-54206 | MEDIUM | 5.9 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in URBAN BASE Z-Downl... |
| CVE-2024-53826 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | Missing Authorization vulnerability in WPSight WPCasa wpcasa allows Accessing Functionality Not Properly Constrained by ... |
| CVE-2024-53823 | MEDIUM | 5.4 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus ... |
| CVE-2024-53820 | MEDIUM | 6.5 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captivateaudio Cap... |
| CVE-2024-53813 | MEDIUM | 6.5 | 0.3% | Dec 6, 2024 | Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Con... |
| CVE-2024-53811 | MEDIUM | 6.6 | 0.3% | Dec 6, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in POSIMYTH WDesignkit wdesignkit allows Upload a Web Shel... |
| CVE-2024-53809 | MEDIUM | 4.3 | 0.2% | Dec 6, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Bob Namaste! LMS namaste-lms allows Cross Site Request Forgery.This i... |
| CVE-2024-53806 | MEDIUM | 5.4 | 0.4% | Dec 6, 2024 | Missing Authorization vulnerability in yonifre Maspik – Spam blacklist contact-forms-anti-spam allows Exploiting Incorre... |
| CVE-2024-53802 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FuturioWP Futurio ... |
| CVE-2024-53801 | MEDIUM | 5.4 | 0.4% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Pa... |
| CVE-2024-53799 | MEDIUM | 4.3 | 0.4% | Dec 6, 2024 | Missing Authorization vulnerability in BAKKBONE Australia FloristPress bakkbone-florist-companion allows Exploiting Inco... |
| CVE-2024-53797 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Bea... |
| CVE-2024-53796 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesf... |
| CVE-2024-53795 | MEDIUM | 5.3 | 0.5% | Dec 6, 2024 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Accessing Functionality Not Properly ... |
| CVE-2024-53794 | MEDIUM | 6.5 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryo Arkhe Blocks a... |
| CVE-2024-4633 | MEDIUM | 6.4 | 0.4% | Dec 6, 2024 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ad... |
| CVE-2024-11321 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hi e-learni... |
| CVE-2024-11022 | MEDIUM | 5.6 | 0.4% | Dec 6, 2024 | The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now