2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50212 | MEDIUM | 5.5 | 0.2% | Nov 9, 2024 | In the Linux kernel, the following vulnerability has been resolved: lib: alloc_tag_module_unload must wait for pending ... |
| CVE-2024-51787 | MEDIUM | 5.4 | 0.2% | Nov 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quomodosoft Elemen... |
| CVE-2024-51786 | MEDIUM | 6.5 | 0.2% | Nov 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bestweblayout Real... |
| CVE-2024-51785 | MEDIUM | 4.4 | 0.2% | Nov 9, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Nks Responsive Filterable Portfolio responsive-filterable-portfolio ... |
| CVE-2024-10876 | MEDIUM | 6.1 | 0.4% | Nov 9, 2024 | The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul... |
| CVE-2024-10688 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Attesa Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.2 ... |
| CVE-2024-10683 | MEDIUM | 6.1 | 0.4% | Nov 9, 2024 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to ... |
| CVE-2024-8756 | MEDIUM | 5.3 | 0.4% | Nov 9, 2024 | The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions... |
| CVE-2024-10814 | MEDIUM | 6.4 | 0.3% | Nov 9, 2024 | The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2... |
| CVE-2024-10770 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 vi... |
| CVE-2024-10669 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Countdown Timer block – Display the event's date into a timer. plugin for WordPress is vulnerable to Informatio... |
| CVE-2024-10667 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Content Slider Block plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including... |
| CVE-2024-9226 | MEDIUM | 6.1 | 0.4% | Nov 9, 2024 | The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Reflecte... |
| CVE-2024-10693 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu... |
| CVE-2024-9775 | MEDIUM | 4.8 | 0.3% | Nov 9, 2024 | The Anih - Creative Agency WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via admin se... |
| CVE-2024-9270 | MEDIUM | 6.4 | 0.3% | Nov 9, 2024 | The Lenxel Core for Lenxel(LNX) LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploa... |
| CVE-2024-9262 | MEDIUM | 6.5 | 0.4% | Nov 9, 2024 | The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Ob... |
| CVE-2024-8960 | MEDIUM | 5.4 | 0.3% | Nov 9, 2024 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ... |
| CVE-2024-10779 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i... |
| CVE-2024-10588 | MEDIUM | 4.3 | 0.3% | Nov 9, 2024 | The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th... |
| CVE-2024-52314 | MEDIUM | 6.9 | 0.4% | Nov 9, 2024 | A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to ... |
| CVE-2024-52313 | MEDIUM | 5.3 | 0.3% | Nov 9, 2024 | An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the pa... |
| CVE-2024-52312 | MEDIUM | 5.4 | 0.3% | Nov 9, 2024 | Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to per... |
| CVE-2024-52311 | MEDIUM | 6.3 | 0.5% | Nov 9, 2024 | Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticat... |
| CVE-2024-10953 | MEDIUM | 5.3 | 0.3% | Nov 9, 2024 | An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now