2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56175 | MEDIUM | 6.1 | 0.2% | Dec 18, 2024 | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ... |
| CVE-2024-56174 | HIGH | 8.1 | 0.4% | Dec 18, 2024 | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ... |
| CVE-2024-56173 | MEDIUM | 4.7 | 0.3% | Dec 18, 2024 | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ... |
| CVE-2024-4464 | HIGH | 7.5 | 0.5% | Dec 18, 2024 | Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-... |
| CVE-2024-21548 | HIGH | 7.5 | 0.6% | Dec 18, 2024 | Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input s... |
| CVE-2024-21547 | HIGH | 7.7 | 0.9% | Dec 18, 2024 | Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation i... |
| CVE-2024-21546 | CRITICAL | 9.8 | 1.3% | Dec 18, 2024 | Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through ... |
| CVE-2024-10892 | MEDIUM | 5.4 | 0.2% | Dec 18, 2024 | The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could a... |
| CVE-2024-56170 | MEDIUM | 5.3 | 0.2% | Dec 18, 2024 | A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant ... |
| CVE-2024-56169 | MEDIUM | 5.3 | 0.2% | Dec 18, 2024 | A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are ... |
| CVE-2024-12698 | MEDIUM | 6.5 | 0.5% | Dec 18, 2024 | An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-4... |
| CVE-2024-12596 | MEDIUM | 4.3 | 0.3% | Dec 18, 2024 | The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post del... |
| CVE-2024-12449 | MEDIUM | 6.4 | 0.3% | Dec 18, 2024 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2024-12432 | HIGH | 8.1 | 0.5% | Dec 18, 2024 | The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalati... |
| CVE-2024-12259 | HIGH | 8.8 | 0.5% | Dec 18, 2024 | The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover i... |
| CVE-2024-12250 | MEDIUM | 5.3 | 0.4% | Dec 18, 2024 | The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all... |
| CVE-2024-12061 | MEDIUM | 4.3 | 0.4% | Dec 18, 2024 | The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc... |
| CVE-2024-12025 | HIGH | 7.5 | 2.5% | Dec 18, 2024 | The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-js... |
| CVE-2024-11254 | MEDIUM | 6.1 | 0.3% | Dec 18, 2024 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the d... |
| CVE-2024-47480 | HIGH | 7.8 | 0.2% | Dec 18, 2024 | Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulne... |
| CVE-2024-12513 | MEDIUM | 6.4 | 0.3% | Dec 18, 2024 | The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONT... |
| CVE-2024-12500 | MEDIUM | 6.4 | 0.4% | Dec 18, 2024 | The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-11881 | MEDIUM | 6.4 | 0.3% | Dec 18, 2024 | The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywavefor... |
| CVE-2024-11748 | MEDIUM | 6.4 | 0.4% | Dec 18, 2024 | The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' short... |
| CVE-2024-11439 | MEDIUM | 6.4 | 0.3% | Dec 18, 2024 | The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'scancircle' shortcode... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now