2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43098 | MEDIUM | 5.5 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: i3c: Use i3cdev->desc->info instead of calling i3c_... |
| CVE-2024-41935 | HIGH | 7.1 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to shrink read extent node in batches We... |
| CVE-2024-41932 | MEDIUM | 5.5 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched: fix warning in sched_setaffinity Commit 8f9... |
| CVE-2024-41149 | HIGH | 7.8 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: block: avoid to reuse `hctx` not removed from cpuhp... |
| CVE-2024-42175 | CRITICAL | 9.8 | 0.3% | Jan 11, 2025 | HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and the... |
| CVE-2024-12877 | CRITICAL | 9.8 | 1.2% | Jan 11, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ... |
| CVE-2024-12527 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The Perfect Portal Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'perfect_p... |
| CVE-2024-12520 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The Dominion – Domain Checker for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu... |
| CVE-2024-12519 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The TCBD Auto Refresher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd_auto_re... |
| CVE-2024-12412 | MEDIUM | 6.1 | 0.3% | Jan 11, 2025 | The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin p... |
| CVE-2024-12407 | MEDIUM | 6.1 | 0.3% | Jan 11, 2025 | The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t... |
| CVE-2024-12116 | MEDIUM | 4.3 | 0.4% | Jan 11, 2025 | The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in al... |
| CVE-2024-11915 | MEDIUM | 4.3 | 0.3% | Jan 11, 2025 | The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi... |
| CVE-2024-11892 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordion_... |
| CVE-2024-11874 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'grid_accordi... |
| CVE-2024-11758 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The WP SPID Italia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all v... |
| CVE-2024-11386 | MEDIUM | 6.4 | 0.3% | Jan 11, 2025 | The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsm... |
| CVE-2024-42174 | LOW | 3.7 | 0.3% | Jan 11, 2025 | HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user to perform enumeration o... |
| CVE-2024-42173 | MEDIUM | 4.8 | 0.2% | Jan 11, 2025 | HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of acco... |
| CVE-2024-42172 | CRITICAL | 9.8 | 0.4% | Jan 11, 2025 | HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tok... |
| CVE-2024-42171 | MEDIUM | 6.4 | 0.2% | Jan 11, 2025 | HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URL... |
| CVE-2024-42170 | MEDIUM | 6.8 | 0.3% | Jan 11, 2025 | HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URL... |
| CVE-2024-12587 | MEDIUM | 6.1 | 0.3% | Jan 11, 2025 | The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-12304 | MEDIUM | 5.4 | 0.2% | Jan 11, 2025 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-42169 | HIGH | 8.1 | 0.3% | Jan 11, 2025 | HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now