2024 CVE Vulnerabilities
39,224 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12519 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The TCBD Auto Refresher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd_auto_re... |
| CVE-2024-12412 | MEDIUM | 6.1 | 0.3% | Jan 11, 2025 | The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin p... |
| CVE-2024-12407 | MEDIUM | 6.1 | 0.3% | Jan 11, 2025 | The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t... |
| CVE-2024-12116 | MEDIUM | 4.3 | 0.4% | Jan 11, 2025 | The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in al... |
| CVE-2024-11915 | MEDIUM | 4.3 | 0.3% | Jan 11, 2025 | The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi... |
| CVE-2024-11892 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordion_... |
| CVE-2024-11874 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'grid_accordi... |
| CVE-2024-11758 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The WP SPID Italia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all v... |
| CVE-2024-11386 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsm... |
| CVE-2024-42174 | LOW | 3.7 | 0.3% | Jan 11, 2025 | HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration o... |
| CVE-2024-42173 | MEDIUM | 4.8 | 0.2% | Jan 11, 2025 | HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of acco... |
| CVE-2024-42172 | CRITICAL | 9.8 | 0.4% | Jan 11, 2025 | HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tok... |
| CVE-2024-42171 | MEDIUM | 6.4 | 0.2% | Jan 11, 2025 | HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URL... |
| CVE-2024-42170 | MEDIUM | 6.8 | 0.3% | Jan 11, 2025 | HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URL... |
| CVE-2024-12587 | MEDIUM | 6.1 | 0.3% | Jan 11, 2025 | The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-12304 | MEDIUM | 5.4 | 0.2% | Jan 11, 2025 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-42169 | HIGH | 8.1 | 0.3% | Jan 11, 2025 | HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which ... |
| CVE-2024-42168 | CRITICAL | 9.4 | 0.4% | Jan 11, 2025 | HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that ... |
| CVE-2024-12627 | HIGH | 7.5 | 0.5% | Jan 11, 2025 | The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne... |
| CVE-2024-12505 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in ... |
| CVE-2024-12472 | MEDIUM | 4.3 | 0.3% | Jan 11, 2025 | The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.3... |
| CVE-2024-12404 | HIGH | 7.5 | 0.8% | Jan 11, 2025 | The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all... |
| CVE-2024-12204 | MEDIUM | 5.4 | 0.2% | Jan 11, 2025 | The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne... |
| CVE-2024-11327 | MEDIUM | 6.1 | 0.3% | Jan 11, 2025 | The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is... |
| CVE-2024-9188 | HIGH | 8.8 | 0.5% | Jan 10, 2025 | Specially constructed queries cause cross platform scripting leaking administrator tokens |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now