2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49673 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Van Abel LaTeX2HTM... |
| CVE-2024-49672 | MEDIUM | 6.1 | 0.2% | Oct 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in giffordcheung Google Docs RSVP google-docs-rsvp-guestlist allows Stor... |
| CVE-2024-49670 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sam Glover Client ... |
| CVE-2024-10360 | MEDIUM | 4.3 | 0.4% | Oct 29, 2024 | The Move Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to... |
| CVE-2024-10266 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Vide... |
| CVE-2024-10233 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2024-10185 | MEDIUM | 6.4 | 0.4% | Oct 29, 2024 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2024-10184 | MEDIUM | 6.4 | 0.4% | Oct 29, 2024 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw... |
| CVE-2024-9376 | MEDIUM | 6.4 | 0.4% | Oct 29, 2024 | The Kata Plus – Addons for Elementor – Widgets, Extensions and Templates plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-10437 | MEDIUM | 4.3 | 0.4% | Oct 29, 2024 | The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to unauthorized Smar Message activation/deacti... |
| CVE-2024-10227 | MEDIUM | 6.4 | 0.3% | Oct 29, 2024 | The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atkp_product sh... |
| CVE-2024-9438 | MEDIUM | 6.1 | 0.4% | Oct 29, 2024 | The SEUR Oficial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'change_service' parameter... |
| CVE-2024-50426 | MEDIUM | 4.8 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak... |
| CVE-2024-50418 | MEDIUM | 6.5 | 0.2% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Time Slot Booking ... |
| CVE-2024-50415 | MEDIUM | 5.9 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagup Ads.txt & Ap... |
| CVE-2024-50414 | MEDIUM | 5.9 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Buttonizer Button ... |
| CVE-2024-50413 | MEDIUM | 5.9 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Javier Carazo Impo... |
| CVE-2024-50412 | MEDIUM | 5.9 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jules Colle Condit... |
| CVE-2024-50411 | MEDIUM | 4.8 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevon Adonis WP Ab... |
| CVE-2024-49642 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rafasashi Todo Cus... |
| CVE-2024-46872 | MEDIUM | 4.6 | 0.1% | Oct 29, 2024 | Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that... |
| CVE-2024-45477 | MEDIUM | 4.6 | 0.6% | Oct 29, 2024 | Apache NiFi 1.10.0 through 1.27.0 and 2.0.0-M1 through 2.0.0-M3 support a description field for Parameters in a Paramete... |
| CVE-2024-22066 | MEDIUM | 6.5 | 0.3% | Oct 29, 2024 | There is a privilege escalation vulnerability in ZTE ZXR10 ZSR V2 intelligent multi service router . An authenticated at... |
| CVE-2024-10048 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ... |
| CVE-2024-50052 | MEDIUM | 4.3 | 0.3% | Oct 29, 2024 | Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now