2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10849 | MEDIUM | 6.4 | 0.3% | Dec 6, 2024 | The NewsMash theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versio... |
| CVE-2024-10692 | MEDIUM | 4.3 | 0.3% | Dec 6, 2024 | The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Informatio... |
| CVE-2024-10689 | MEDIUM | 4.3 | 0.3% | Dec 6, 2024 | The XLTab – Accordions and Tabs for Elementor Page Builder plugin for WordPress is vulnerable to Information Exposure in... |
| CVE-2024-10320 | MEDIUM | 6.4 | 0.3% | Dec 6, 2024 | The Cookielay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookielay shortcode in ... |
| CVE-2024-11201 | MEDIUM | 6.4 | 0.8% | Dec 6, 2024 | The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo... |
| CVE-2024-10551 | MEDIUM | 4.8 | 0.3% | Dec 6, 2024 | The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-10480 | MEDIUM | 4.3 | 0.2% | Dec 6, 2024 | The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could a... |
| CVE-2024-11379 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all v... |
| CVE-2024-9769 | MEDIUM | 4.8 | 0.3% | Dec 6, 2024 | The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-10836 | MEDIUM | 6.1 | 0.4% | Dec 6, 2024 | The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions u... |
| CVE-2024-10247 | MEDIUM | 4.9 | 0.5% | Dec 6, 2024 | The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection... |
| CVE-2024-49041 | MEDIUM | 4.3 | 1.1% | Dec 6, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-11149 | MEDIUM | 5.5 | 0.1% | Dec 6, 2024 | In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs. |
| CVE-2024-53457 | MEDIUM | 5.4 | 42.5% | Dec 5, 2024 | A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows ... |
| CVE-2024-10933 | MEDIUM | 5.5 | 0.3% | Dec 5, 2024 | In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid ... |
| CVE-2024-54128 | MEDIUM | 4.6 | 0.3% | Dec 5, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a f... |
| CVE-2024-53846 | MEDIUM | 5.5 | 0.2% | Dec 5, 2024 | OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainl... |
| CVE-2024-54001 | MEDIUM | 5.5 | 0.4% | Dec 5, 2024 | Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the... |
| CVE-2024-53471 | MEDIUM | 6.1 | 0.3% | Dec 5, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3... |
| CVE-2024-53470 | MEDIUM | 6.1 | 0.4% | Dec 5, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA... |
| CVE-2024-12247 | MEDIUM | 4.3 | 0.2% | Dec 5, 2024 | Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updat... |
| CVE-2024-12232 | MEDIUM | 6.1 | 0.4% | Dec 5, 2024 | A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulner... |
| CVE-2024-10716 | MEDIUM | 4.8 | 0.2% | Dec 5, 2024 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. |
| CVE-2024-11942 | MEDIUM | 5.9 | 0.4% | Dec 5, 2024 | A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10. |
| CVE-2024-54679 | MEDIUM | 6.5 | 0.9% | Dec 5, 2024 | CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now