2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12594 | HIGH | 8.8 | 0.7% | Dec 24, 2024 | The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Tempora... |
| CVE-2024-12405 | MEDIUM | 6.1 | 0.3% | Dec 24, 2024 | The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in ... |
| CVE-2024-12210 | MEDIUM | 4.3 | 0.3% | Dec 24, 2024 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da... |
| CVE-2024-12100 | MEDIUM | 6.1 | 0.3% | Dec 24, 2024 | The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t... |
| CVE-2024-12096 | MEDIUM | 6.1 | 0.3% | Dec 24, 2024 | The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it b... |
| CVE-2024-12034 | MEDIUM | 5.3 | 0.3% | Dec 24, 2024 | The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, ... |
| CVE-2024-11885 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njte... |
| CVE-2024-12710 | MEDIUM | 6.1 | 0.3% | Dec 24, 2024 | The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versi... |
| CVE-2024-12617 | MEDIUM | 5.4 | 0.3% | Dec 24, 2024 | The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability c... |
| CVE-2024-12518 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' sho... |
| CVE-2024-12507 | MEDIUM | 6.4 | 0.3% | Dec 24, 2024 | The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' ... |
| CVE-2024-12266 | MEDIUM | 6.5 | 0.3% | Dec 24, 2024 | The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due... |
| CVE-2024-9427 | MEDIUM | 5.4 | 0.3% | Dec 24, 2024 | A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link ... |
| CVE-2024-47515 | HIGH | 8.1 | 0.5% | Dec 24, 2024 | A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the di... |
| CVE-2024-12582 | HIGH | 7.1 | 0.5% | Dec 24, 2024 | A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metri... |
| CVE-2024-53961 | HIGH | 8.1 | 13.4% | Dec 23, 2024 | ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Di... |
| CVE-2024-56363 | HIGH | 7.8 | 0.3% | Dec 23, 2024 | APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed fo... |
| CVE-2024-56362 | MEDIUM | 5.5 | 0.1% | Dec 23, 2024 | Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext... |
| CVE-2024-53276 | MEDIUM | 6.3 | 0.5% | Dec 23, 2024 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, a... |
| CVE-2024-53275 | MEDIUM | 5.3 | 0.3% | Dec 23, 2024 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, t... |
| CVE-2024-40896 | CRITICAL | 9.1 | 1.2% | Dec 23, 2024 | In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for externa... |
| CVE-2024-56364 | MEDIUM | 5.4 | 0.2% | Dec 23, 2024 | SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, w... |
| CVE-2024-56326 | HIGH | 7.8 | 0.5% | Dec 23, 2024 | Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects ca... |
| CVE-2024-56201 | HIGH | 8.8 | 0.3% | Dec 23, 2024 | Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allo... |
| CVE-2024-55947 | HIGH | 8.8 | 75.2% | Dec 23, 2024 | Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the ser... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now