2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12219 | MEDIUM | 6.1 | 0.2% | Dec 17, 2024 | The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-11999 | HIGH | 8.8 | 0.6% | Dec 17, 2024 | CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the devic... |
| CVE-2024-9624 | HIGH | 7.6 | 0.4% | Dec 17, 2024 | The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu... |
| CVE-2024-54125 | LOW | 3.3 | 0.2% | Dec 17, 2024 | Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 ... |
| CVE-2024-38499 | HIGH | 8.8 | 0.2% | Dec 17, 2024 | CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This woul... |
| CVE-2024-55864 | MEDIUM | 4.8 | 0.3% | Dec 17, 2024 | Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious... |
| CVE-2024-12356 | CRITICAL | 9.8 | 88.0% | Dec 17, 2024 | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which ca... |
| CVE-2024-12239 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navig... |
| CVE-2024-10205 | CRITICAL | 9.4 | 0.8% | Dec 17, 2024 | Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail ... |
| CVE-2024-11906 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The TPG Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpg_get_posts' sho... |
| CVE-2024-11905 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animatedcounte... |
| CVE-2024-11902 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations... |
| CVE-2024-11900 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-56017 | HIGH | 7.1 | 0.1% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects... |
| CVE-2024-55452 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of ... |
| CVE-2024-55451 | MEDIUM | 4.8 | 0.3% | Dec 16, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in U... |
| CVE-2024-55085 | CRITICAL | 9.8 | 0.8% | Dec 16, 2024 | GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background managem... |
| CVE-2024-35230 | MEDIUM | 5.3 | 0.7% | Dec 16, 2024 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affe... |
| CVE-2024-12443 | MEDIUM | 6.4 | 0.3% | Dec 16, 2024 | The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Sto... |
| CVE-2024-55554 | MEDIUM | 5.4 | 0.2% | Dec 16, 2024 | Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet. |
| CVE-2024-52949 | HIGH | 7.5 | 0.7% | Dec 16, 2024 | iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control th... |
| CVE-2024-37776 | MEDIUM | 4.8 | 0.3% | Dec 16, 2024 | A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scri... |
| CVE-2024-37775 | HIGH | 7.5 | 0.4% | Dec 16, 2024 | Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location wh... |
| CVE-2024-37774 | HIGH | 8 | 0.2% | Dec 16, 2024 | A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their priv... |
| CVE-2024-37773 | MEDIUM | 4.8 | 0.2% | Dec 16, 2024 | An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now