2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11782 | MEDIUM | 5.4 | 0.3% | Dec 3, 2024 | The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' short... |
| CVE-2024-11325 | MEDIUM | 5.2 | 0.9% | Dec 3, 2024 | The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add... |
| CVE-2024-11866 | MEDIUM | 6.4 | 0.2% | Dec 3, 2024 | The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map'... |
| CVE-2024-11844 | MEDIUM | 4.3 | 0.3% | Dec 3, 2024 | The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2024-11898 | MEDIUM | 5.4 | 0.3% | Dec 3, 2024 | The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin... |
| CVE-2024-11853 | MEDIUM | 6.4 | 0.3% | Dec 3, 2024 | The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versio... |
| CVE-2024-11805 | MEDIUM | 6.1 | 0.3% | Dec 3, 2024 | The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ... |
| CVE-2024-11732 | MEDIUM | 6.5 | 0.4% | Dec 3, 2024 | The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the ‘tab’ parameter i... |
| CVE-2024-11707 | MEDIUM | 6.1 | 0.4% | Dec 3, 2024 | The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in... |
| CVE-2024-11461 | MEDIUM | 6.1 | 0.3% | Dec 3, 2024 | The Form Data Collector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in... |
| CVE-2024-11453 | MEDIUM | 5.4 | 0.3% | Dec 3, 2024 | The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerab... |
| CVE-2024-9058 | MEDIUM | 5.4 | 0.2% | Dec 3, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-49421 | MEDIUM | 4.3 | 0.3% | Dec 3, 2024 | Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in ... |
| CVE-2024-49419 | MEDIUM | 4.3 | 0.4% | Dec 3, 2024 | Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows... |
| CVE-2024-49418 | MEDIUM | 6.5 | 0.4% | Dec 3, 2024 | Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows... |
| CVE-2024-49416 | MEDIUM | 5.5 | 0.1% | Dec 3, 2024 | Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get ... |
| CVE-2024-49412 | MEDIUM | 5.5 | 0.1% | Dec 3, 2024 | Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for dis... |
| CVE-2024-49411 | MEDIUM | 4.6 | 0.2% | Dec 3, 2024 | Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary p... |
| CVE-2024-10893 | MEDIUM | 4.8 | 0.3% | Dec 3, 2024 | The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-10484 | MEDIUM | 5.4 | 0.3% | Dec 3, 2024 | The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-9694 | MEDIUM | 6.4 | 0.3% | Dec 3, 2024 | The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in... |
| CVE-2024-9197 | MEDIUM | 4.9 | 0.5% | Dec 3, 2024 | A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B f... |
| CVE-2024-53988 | MEDIUM | 6.1 | 0.4% | Dec 2, 2024 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera... |
| CVE-2024-53987 | MEDIUM | 6.1 | 0.4% | Dec 2, 2024 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera... |
| CVE-2024-53986 | MEDIUM | 6.1 | 0.5% | Dec 2, 2024 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now