2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53147 | HIGH | 7.1 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entrie... |
| CVE-2024-53146 | MEDIUM | 5.5 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the ... |
| CVE-2024-53145 | MEDIUM | 5.5 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: um: Fix potential integer overflow during physmem s... |
| CVE-2024-43441 | CRITICAL | 9.8 | 69.7% | Dec 24, 2024 | Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache Hug... |
| CVE-2024-12268 | MEDIUM | 5.4 | 0.3% | Dec 24, 2024 | The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-11726 | MEDIUM | 6.5 | 0.5% | Dec 24, 2024 | The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL I... |
| CVE-2024-10856 | MEDIUM | 6.5 | 0.5% | Dec 24, 2024 | The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpd... |
| CVE-2024-10584 | MEDIUM | 5.4 | 0.3% | Dec 24, 2024 | The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Stored Cross-Sit... |
| CVE-2024-8721 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The Tracking Code Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tracking code field ... |
| CVE-2024-53241 | MEDIUM | 5.5 | 0.3% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: x86/xen: don't do PV iret hypercall through hyperca... |
| CVE-2024-53240 | MEDIUM | 5.7 | 0.6% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: xen/netfront: fix crash when removing device When ... |
| CVE-2024-12881 | HIGH | 8.8 | 0.4% | Dec 24, 2024 | The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary ... |
| CVE-2024-12850 | MEDIUM | 4.9 | 0.8% | Dec 24, 2024 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Trave... |
| CVE-2024-12103 | MEDIUM | 5.3 | 0.4% | Dec 24, 2024 | The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Expos... |
| CVE-2024-12031 | MEDIUM | 6.5 | 0.4% | Dec 24, 2024 | The Advanced Floating Content plugin for WordPress is vulnerable to SQL Injection via the 'floating_content_duplicate_po... |
| CVE-2024-12468 | MEDIUM | 6.1 | 0.4% | Dec 24, 2024 | The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepi... |
| CVE-2024-11896 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-12814 | MEDIUM | 6.4 | 0.4% | Dec 24, 2024 | The Loan Comparison plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'loancomparison' ... |
| CVE-2024-41887 | MEDIUM | 5.1 | 1.0% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can... |
| CVE-2024-41886 | MEDIUM | 6.9 | 0.6% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker cou... |
| CVE-2024-41885 | MEDIUM | 5.6 | 0.2% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. The seed string... |
| CVE-2024-41884 | MEDIUM | 6.9 | 0.8% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. If an attacker ... |
| CVE-2024-41883 | MEDIUM | 6.9 | 0.6% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR . An attacker... |
| CVE-2024-41882 | MEDIUM | 6.9 | 0.6% | Dec 24, 2024 | Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can... |
| CVE-2024-12622 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now