2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9819 | MEDIUM | 6.5 | 0.4% | Dec 17, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse.... |
| CVE-2024-54677 | MEDIUM | 5.3 | 1.9% | Dec 17, 2024 | Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to den... |
| CVE-2024-50379 | CRITICAL | 9.8 | 42.3% | Dec 17, 2024 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE o... |
| CVE-2024-10356 | MEDIUM | 4.3 | 0.4% | Dec 17, 2024 | The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi... |
| CVE-2024-9654 | LOW | 3.7 | 0.3% | Dec 17, 2024 | The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. T... |
| CVE-2024-8475 | MEDIUM | 6.5 | 0.4% | Dec 17, 2024 | Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulati... |
| CVE-2024-8429 | MEDIUM | 4.3 | 0.4% | Dec 17, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows ... |
| CVE-2024-52542 | MEDIUM | 5.5 | 0.2% | Dec 17, 2024 | Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with... |
| CVE-2024-12601 | MEDIUM | 5.3 | 0.5% | Dec 17, 2024 | The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including,... |
| CVE-2024-12395 | MEDIUM | 6.1 | 0.5% | Dec 17, 2024 | The WooCommerce Additional Fees On Checkout (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-11280 | MEDIUM | 5.3 | 0.4% | Dec 17, 2024 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u... |
| CVE-2024-8326 | HIGH | 8.8 | 0.6% | Dec 17, 2024 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin... |
| CVE-2024-12469 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2024-12127 | MEDIUM | 6.1 | 0.3% | Dec 17, 2024 | The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vu... |
| CVE-2024-12024 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-12293 | HIGH | 8.8 | 0.3% | Dec 17, 2024 | The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2024-11294 | MEDIUM | 5.3 | 0.5% | Dec 17, 2024 | The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-12220 | MEDIUM | 6.1 | 0.2% | Dec 17, 2024 | The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2024-12219 | MEDIUM | 6.1 | 0.2% | Dec 17, 2024 | The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-11999 | HIGH | 8.8 | 0.6% | Dec 17, 2024 | CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the devic... |
| CVE-2024-9624 | HIGH | 7.6 | 0.4% | Dec 17, 2024 | The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu... |
| CVE-2024-54125 | LOW | 3.3 | 0.2% | Dec 17, 2024 | Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 ... |
| CVE-2024-38499 | HIGH | 8.8 | 0.2% | Dec 17, 2024 | CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This woul... |
| CVE-2024-55864 | MEDIUM | 4.8 | 0.3% | Dec 17, 2024 | Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious... |
| CVE-2024-12356 | CRITICAL | 9.8 | 88.0% | Dec 17, 2024 | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which ca... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now