2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54206 | MEDIUM | 5.9 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in URBAN BASE Z-Downl... |
| CVE-2024-53826 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | Missing Authorization vulnerability in WPSight WPCasa wpcasa allows Accessing Functionality Not Properly Constrained by ... |
| CVE-2024-53823 | MEDIUM | 5.4 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus ... |
| CVE-2024-53820 | MEDIUM | 6.5 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in captivateaudio Cap... |
| CVE-2024-53813 | MEDIUM | 6.5 | 0.3% | Dec 6, 2024 | Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Con... |
| CVE-2024-53811 | MEDIUM | 6.6 | 0.3% | Dec 6, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in POSIMYTH WDesignkit wdesignkit allows Upload a Web Shel... |
| CVE-2024-53809 | MEDIUM | 4.3 | 0.2% | Dec 6, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Bob Namaste! LMS namaste-lms allows Cross Site Request Forgery.This i... |
| CVE-2024-53806 | MEDIUM | 5.4 | 0.4% | Dec 6, 2024 | Missing Authorization vulnerability in yonifre Maspik – Spam blacklist contact-forms-anti-spam allows Exploiting Incorre... |
| CVE-2024-53802 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FuturioWP Futurio ... |
| CVE-2024-53801 | MEDIUM | 5.4 | 0.4% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Pa... |
| CVE-2024-53799 | MEDIUM | 4.3 | 0.4% | Dec 6, 2024 | Missing Authorization vulnerability in BAKKBONE Australia FloristPress bakkbone-florist-companion allows Exploiting Inco... |
| CVE-2024-53797 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Beaver Builder Bea... |
| CVE-2024-53796 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesf... |
| CVE-2024-53795 | MEDIUM | 5.3 | 0.5% | Dec 6, 2024 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Accessing Functionality Not Properly ... |
| CVE-2024-53794 | MEDIUM | 6.5 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryo Arkhe Blocks a... |
| CVE-2024-4633 | MEDIUM | 6.4 | 0.4% | Dec 6, 2024 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ad... |
| CVE-2024-11321 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hi e-learni... |
| CVE-2024-11022 | MEDIUM | 5.6 | 0.4% | Dec 6, 2024 | The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional ... |
| CVE-2024-11730 | MEDIUM | 6.5 | 0.4% | Dec 6, 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sor... |
| CVE-2024-11729 | MEDIUM | 6.5 | 0.6% | Dec 6, 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'ser... |
| CVE-2024-10909 | MEDIUM | 6.3 | 0.4% | Dec 6, 2024 | The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX a... |
| CVE-2024-10681 | MEDIUM | 6.3 | 0.4% | Dec 6, 2024 | The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPres... |
| CVE-2024-9872 | MEDIUM | 5.4 | 0.2% | Dec 6, 2024 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2024-9866 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' p... |
| CVE-2024-9706 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now