2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11814 | MEDIUM | 6.1 | 0.3% | Dec 4, 2024 | The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-5020 | MEDIUM | 6.4 | 0.4% | Dec 4, 2024 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScrip... |
| CVE-2024-11880 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-10787 | MEDIUM | 4.3 | 0.3% | Dec 4, 2024 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to... |
| CVE-2024-11903 | MEDIUM | 6.4 | 0.2% | Dec 4, 2024 | The WP eCards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ecard' shortcode in al... |
| CVE-2024-11769 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'f... |
| CVE-2024-11466 | MEDIUM | 6.1 | 0.3% | Dec 4, 2024 | The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't... |
| CVE-2024-10664 | MEDIUM | 4.3 | 0.3% | Dec 4, 2024 | The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2024-45717 | MEDIUM | 4.8 | 0.4% | Dec 4, 2024 | The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of t... |
| CVE-2024-12123 | MEDIUM | 5.3 | 0.4% | Dec 4, 2024 | A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authent... |
| CVE-2024-12099 | MEDIUM | 4.3 | 0.3% | Dec 4, 2024 | The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in a... |
| CVE-2024-10885 | MEDIUM | 5.4 | 0.3% | Dec 4, 2024 | The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's... |
| CVE-2024-11897 | MEDIUM | 5.4 | 0.3% | Dec 4, 2024 | The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-11813 | MEDIUM | 6.1 | 0.2% | Dec 4, 2024 | The Pulsating Chat Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-11807 | MEDIUM | 6.1 | 0.3% | Dec 4, 2024 | The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' paramet... |
| CVE-2024-11747 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortc... |
| CVE-2024-11093 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due ... |
| CVE-2024-10832 | MEDIUM | 6.1 | 0.4% | Dec 4, 2024 | The Posti Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the account_number and secre... |
| CVE-2024-10663 | MEDIUM | 4.3 | 0.2% | Dec 4, 2024 | The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-45206 | MEDIUM | 6.5 | 0.2% | Dec 4, 2024 | A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests t... |
| CVE-2024-45204 | MEDIUM | 4.3 | 0.4% | Dec 4, 2024 | A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak N... |
| CVE-2024-42457 | MEDIUM | 6.5 | 0.4% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by le... |
| CVE-2024-42451 | MEDIUM | 6.5 | 0.3% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. Th... |
| CVE-2024-11985 | MEDIUM | 4.4 | 0.3% | Dec 4, 2024 | An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2... |
| CVE-2024-11479 | MEDIUM | 5.1 | 0.4% | Dec 4, 2024 | A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now