2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10696 | MEDIUM | 4.3 | 0.5% | Nov 21, 2024 | The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere El... |
| CVE-2024-10682 | MEDIUM | 6.1 | 0.6% | Nov 21, 2024 | The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting d... |
| CVE-2024-10675 | MEDIUM | 6.1 | 0.4% | Nov 21, 2024 | The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up ... |
| CVE-2024-10671 | MEDIUM | 6.5 | 0.5% | Nov 21, 2024 | The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information E... |
| CVE-2024-10623 | MEDIUM | 6.1 | 0.4% | Nov 21, 2024 | The ForumEngine theme for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and... |
| CVE-2024-10532 | MEDIUM | 4.3 | 0.5% | Nov 21, 2024 | The Bard Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-10528 | MEDIUM | 4.3 | 0.6% | Nov 21, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2024-10522 | MEDIUM | 6.1 | 0.6% | Nov 21, 2024 | The Co-marquage service-public.fr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of... |
| CVE-2024-10482 | MEDIUM | 5.4 | 0.4% | Nov 21, 2024 | The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does n... |
| CVE-2024-10393 | MEDIUM | 5.3 | 0.6% | Nov 21, 2024 | The Tutor LMS plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 2.7.6.... |
| CVE-2024-10316 | MEDIUM | 4.3 | 0.5% | Nov 21, 2024 | The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up ... |
| CVE-2024-10177 | MEDIUM | 6.4 | 0.6% | Nov 21, 2024 | The Beds24 Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's beds24-link... |
| CVE-2024-10172 | MEDIUM | 5.4 | 0.5% | Nov 21, 2024 | The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-10164 | MEDIUM | 6.4 | 0.5% | Nov 21, 2024 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-52755 | MEDIUM | 4.9 | 0.8% | Nov 21, 2024 | D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the host_ip parameter in the ipsec_road_asp f... |
| CVE-2024-52702 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | A stored cross-site scripting (XSS) vulnerability in the component install\index.php of MyBB v1.8.38 allows attackers to... |
| CVE-2024-52701 | MEDIUM | 5.4 | 0.2% | Nov 20, 2024 | A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execut... |
| CVE-2024-48535 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary ... |
| CVE-2024-48534 | MEDIUM | 5.4 | 0.4% | Nov 20, 2024 | A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows a... |
| CVE-2024-48533 | MEDIUM | 5.3 | 0.4% | Nov 20, 2024 | A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner ... |
| CVE-2024-48531 | MEDIUM | 5.4 | 0.4% | Nov 20, 2024 | A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA a... |
| CVE-2024-52757 | MEDIUM | 4.9 | 0.6% | Nov 20, 2024 | D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp funct... |
| CVE-2024-52754 | MEDIUM | 4.9 | 0.6% | Nov 20, 2024 | D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function. |
| CVE-2024-45510 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored... |
| CVE-2024-45511 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now