2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13240 | HIGH | 7.5 | 0.4% | Jan 9, 2025 | Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issu... |
| CVE-2024-13239 | CRITICAL | 9.8 | 0.5% | Jan 9, 2025 | Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affec... |
| CVE-2024-13238 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Typogrify a... |
| CVE-2024-13237 | MEDIUM | 5.4 | 0.2% | Jan 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity... |
| CVE-2024-10106 | LOW | 3.7 | 0.4% | Jan 9, 2025 | A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's... |
| CVE-2024-43176 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should o... |
| CVE-2024-6155 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Ser... |
| CVE-2024-5769 | MEDIUM | 4.3 | 0.4% | Jan 9, 2025 | The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-12848 | HIGH | 8.8 | 0.9% | Jan 9, 2025 | The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on t... |
| CVE-2024-12819 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortc... |
| CVE-2024-12621 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' ... |
| CVE-2024-12618 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2024-12616 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-12605 | MEDIUM | 4.3 | 0.2% | Jan 9, 2025 | The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch... |
| CVE-2024-12542 | HIGH | 8.6 | 1.3% | Jan 9, 2025 | The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when incl... |
| CVE-2024-12515 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID ... |
| CVE-2024-12514 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' short... |
| CVE-2024-12496 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissi... |
| CVE-2024-12493 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' sh... |
| CVE-2024-12491 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_se... |
| CVE-2024-12394 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all ... |
| CVE-2024-12330 | HIGH | 7.5 | 0.5% | Jan 9, 2025 | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensit... |
| CVE-2024-12285 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versi... |
| CVE-2024-12249 | MEDIUM | 4.3 | 0.3% | Jan 9, 2025 | The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2024-12222 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvs... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now