2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51466 | CRITICAL | 9 | 0.6% | Dec 20, 2024 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL)... |
| CVE-2024-40695 | HIGH | 8 | 0.4% | Dec 20, 2024 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file uplo... |
| CVE-2024-28767 | HIGH | 8.8 | 0.6% | Dec 20, 2024 | IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated at... |
| CVE-2024-12014 | LOW | 2 | 0.3% | Dec 20, 2024 | Path Traversal vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow ... |
| CVE-2024-7726 | MEDIUM | 6.8 | 0.4% | Dec 20, 2024 | There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and... |
| CVE-2024-9619 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The WP SHAPES plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up ... |
| CVE-2024-9503 | MEDIUM | 4.3 | 0.3% | Dec 20, 2024 | The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-12571 | CRITICAL | 9.8 | 0.9% | Dec 20, 2024 | The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclus... |
| CVE-2024-12509 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Embed Twine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_twine' shortco... |
| CVE-2024-12506 | MEDIUM | 6.4 | 0.4% | Dec 20, 2024 | The NACC WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nacc' shor... |
| CVE-2024-11893 | MEDIUM | 6.4 | 0.4% | Dec 20, 2024 | The Spoki – Chat Buttons and WooCommerce Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-11878 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Category Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'category-po... |
| CVE-2024-11812 | MEDIUM | 6.1 | 0.2% | Dec 20, 2024 | The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2024-11806 | MEDIUM | 6.1 | 0.3% | Dec 20, 2024 | The PKT1 Centro de envios plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'success' and 'er... |
| CVE-2024-11784 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Sell Tickets Online – TicketSource Ticket Shop for WordPress plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2024-11783 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Financial Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'finance_cal... |
| CVE-2024-11775 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particlegrou... |
| CVE-2024-11774 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Outdooractive Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list2go' sho... |
| CVE-2024-11411 | MEDIUM | 6.4 | 0.3% | Dec 20, 2024 | The Spotlightr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotlightr-v' shortco... |
| CVE-2024-11331 | MEDIUM | 6.1 | 0.4% | Dec 20, 2024 | The استخراج محصولات ووکامرس برای آیسی plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us... |
| CVE-2024-11297 | HIGH | 7.5 | 0.6% | Dec 20, 2024 | The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information ... |
| CVE-2024-8968 | MEDIUM | 4.7 | 0.4% | Dec 20, 2024 | The WordPress Button Plugin MaxButtons WordPress plugin before 9.8.1 does not sanitise and escape some of its settings, ... |
| CVE-2024-5955 | MEDIUM | 5.4 | 0.4% | Dec 20, 2024 | Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a re... |
| CVE-2024-11108 | MEDIUM | 5.4 | 0.3% | Dec 20, 2024 | The Serious Slider WordPress plugin before 1.2.7 does not validate and escape some of its shortcode attributes before ou... |
| CVE-2024-10706 | MEDIUM | 4.8 | 0.3% | Dec 20, 2024 | The Download Manager WordPress plugin before 3.3.03 does not sanitise and escape some of its settings, which could allow... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now