2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7747 | MEDIUM | 6.5 | 0.5% | Nov 28, 2024 | The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versi... |
| CVE-2024-53731 | MEDIUM | 6.5 | 0.3% | Nov 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fintelligence Fint... |
| CVE-2024-8308 | MEDIUM | 6.5 | 0.6% | Nov 28, 2024 | A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP requ... |
| CVE-2024-53737 | MEDIUM | 5.4 | 0.3% | Nov 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mails... |
| CVE-2024-52283 | MEDIUM | 5.7 | 0.3% | Nov 28, 2024 | Missing sanitation of inputs allowed arbitrary users to conduct a stored XSS attack that triggers for users that view a ... |
| CVE-2024-49503 | MEDIUM | 4.6 | 0.3% | Nov 28, 2024 | A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE mana... |
| CVE-2024-49502 | MEDIUM | 4.6 | 0.3% | Nov 28, 2024 | A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup... |
| CVE-2024-22037 | MEDIUM | 5.7 | 0.2% | Nov 28, 2024 | The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permissio... |
| CVE-2024-11599 | MEDIUM | 5.3 | 0.5% | Nov 28, 2024 | Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate emai... |
| CVE-2024-10798 | MEDIUM | 4.3 | 0.4% | Nov 28, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t... |
| CVE-2024-10780 | MEDIUM | 4.3 | 0.4% | Nov 28, 2024 | The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up ... |
| CVE-2024-10670 | MEDIUM | 4.3 | 0.4% | Nov 28, 2024 | The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in... |
| CVE-2024-11788 | MEDIUM | 6.4 | 0.4% | Nov 28, 2024 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2024-11786 | MEDIUM | 6.4 | 0.4% | Nov 28, 2024 | The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c... |
| CVE-2024-11761 | MEDIUM | 6.4 | 0.3% | Nov 28, 2024 | The LegalWeb Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'legalweb-popup' s... |
| CVE-2024-11685 | MEDIUM | 6.1 | 0.3% | Nov 28, 2024 | The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Si... |
| CVE-2024-11684 | MEDIUM | 6.1 | 0.4% | Nov 28, 2024 | The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Site... |
| CVE-2024-11458 | MEDIUM | 6.1 | 0.4% | Nov 28, 2024 | The FAQ Builder AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_faq_tab' parameter... |
| CVE-2024-11431 | MEDIUM | 6.4 | 0.4% | Nov 28, 2024 | The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode... |
| CVE-2024-11366 | MEDIUM | 6.1 | 0.4% | Nov 28, 2024 | The SEO Landing Page Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad... |
| CVE-2024-11333 | MEDIUM | 6.4 | 0.3% | Nov 28, 2024 | The HLS Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hls_player' shortcode... |
| CVE-2024-11203 | MEDIUM | 5.4 | 0.4% | Nov 28, 2024 | The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps i... |
| CVE-2024-11918 | MEDIUM | 4.3 | 0.3% | Nov 28, 2024 | The Image Alt Text plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability ... |
| CVE-2024-10896 | MEDIUM | 5.4 | 0.4% | Nov 28, 2024 | The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which ... |
| CVE-2024-10510 | MEDIUM | 4.8 | 0.4% | Nov 28, 2024 | The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now