2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9610 | MEDIUM | 6.1 | 0.3% | Oct 11, 2024 | The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a... |
| CVE-2024-9587 | MEDIUM | 4.3 | 0.4% | Oct 11, 2024 | The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2024-9586 | MEDIUM | 5.3 | 0.4% | Oct 11, 2024 | The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2024-9543 | MEDIUM | 6.4 | 0.3% | Oct 11, 2024 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-9538 | MEDIUM | 6.5 | 0.4% | Oct 11, 2024 | The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2024-9507 | MEDIUM | 4.9 | 0.5% | Oct 11, 2024 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
| CVE-2024-9436 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner... |
| CVE-2024-9346 | MEDIUM | 6.1 | 0.3% | Oct 11, 2024 | The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' pa... |
| CVE-2024-9232 | MEDIUM | 6.1 | 0.3% | Oct 11, 2024 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripti... |
| CVE-2024-9221 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou... |
| CVE-2024-9211 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | The FULL – Cliente plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ... |
| CVE-2024-9051 | MEDIUM | 6.4 | 0.3% | Oct 11, 2024 | The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-... |
| CVE-2024-8913 | MEDIUM | 4.3 | 0.4% | Oct 11, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-7514 | MEDIUM | 6.5 | 1.0% | Oct 11, 2024 | The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient ... |
| CVE-2024-6971 | MEDIUM | 4.4 | 0.3% | Oct 11, 2024 | A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.p... |
| CVE-2024-5005 | MEDIUM | 4.3 | 0.4% | Oct 11, 2024 | An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all ver... |
| CVE-2024-48987 | MEDIUM | 6.6 | 1.0% | Oct 11, 2024 | Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the AP... |
| CVE-2024-45315 | MEDIUM | 5.5 | 0.2% | Oct 11, 2024 | The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12... |
| CVE-2024-47872 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **Cross-Site Scripti... |
| CVE-2024-47168 | MEDIUM | 4.3 | 0.3% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to... |
| CVE-2024-47166 | MEDIUM | 5.3 | 0.4% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read p... |
| CVE-2024-47165 | MEDIUM | 5.4 | 0.3% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **CORS origin vali... |
| CVE-2024-47164 | MEDIUM | 6.5 | 0.7% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of di... |
| CVE-2024-9810 | MEDIUM | 6.1 | 0.4% | Oct 10, 2024 | A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as problematic. Affected by ... |
| CVE-2024-9809 | MEDIUM | 6.5 | 0.4% | Oct 10, 2024 | A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now