2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8962 | MEDIUM | 5.4 | 0.3% | Dec 4, 2024 | The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG F... |
| CVE-2024-54158 | MEDIUM | 5.3 | 0.3% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding |
| CVE-2024-54157 | MEDIUM | 6.5 | 0.6% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector |
| CVE-2024-54156 | MEDIUM | 6.5 | 0.3% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack |
| CVE-2024-54155 | MEDIUM | 5.3 | 0.4% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import wit... |
| CVE-2024-54153 | MEDIUM | 6.5 | 0.4% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query par... |
| CVE-2024-11854 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The Listdom – Business Directory and Classified Ads Listings WordPress Plugin plugin for WordPress is vulnerable to Stor... |
| CVE-2024-11814 | MEDIUM | 6.1 | 0.3% | Dec 4, 2024 | The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-5020 | MEDIUM | 6.4 | 0.4% | Dec 4, 2024 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScrip... |
| CVE-2024-11880 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-10787 | MEDIUM | 4.3 | 0.3% | Dec 4, 2024 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to... |
| CVE-2024-11903 | MEDIUM | 6.4 | 0.2% | Dec 4, 2024 | The WP eCards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ecard' shortcode in al... |
| CVE-2024-11769 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'f... |
| CVE-2024-11466 | MEDIUM | 6.1 | 0.3% | Dec 4, 2024 | The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't... |
| CVE-2024-10664 | MEDIUM | 4.3 | 0.3% | Dec 4, 2024 | The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2024-45717 | MEDIUM | 4.8 | 0.4% | Dec 4, 2024 | The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of t... |
| CVE-2024-12123 | MEDIUM | 5.3 | 0.4% | Dec 4, 2024 | A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authent... |
| CVE-2024-12099 | MEDIUM | 4.3 | 0.3% | Dec 4, 2024 | The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in a... |
| CVE-2024-10885 | MEDIUM | 5.4 | 0.3% | Dec 4, 2024 | The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's... |
| CVE-2024-11897 | MEDIUM | 5.4 | 0.3% | Dec 4, 2024 | The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-11813 | MEDIUM | 6.1 | 0.2% | Dec 4, 2024 | The Pulsating Chat Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-11807 | MEDIUM | 6.1 | 0.3% | Dec 4, 2024 | The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' paramet... |
| CVE-2024-11747 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortc... |
| CVE-2024-11093 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due ... |
| CVE-2024-10832 | MEDIUM | 6.1 | 0.4% | Dec 4, 2024 | The Posti Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the account_number and secre... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now