2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9290 | CRITICAL | 9.8 | 3.5% | Dec 13, 2024 | The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to mis... |
| CVE-2024-52057 | CRITICAL | 9.8 | 0.4% | Dec 13, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Profes... |
| CVE-2024-11012 | MEDIUM | 6.3 | 0.5% | Dec 13, 2024 | The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via... |
| CVE-2024-10783 | HIGH | 8.1 | 2.3% | Dec 13, 2024 | The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable... |
| CVE-2024-12465 | MEDIUM | 6.4 | 0.3% | Dec 13, 2024 | The Property Hive Stamp Duty Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-12421 | MEDIUM | 6.5 | 0.5% | Dec 13, 2024 | The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-12420 | MEDIUM | 6.5 | 0.4% | Dec 13, 2024 | The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode exec... |
| CVE-2024-12417 | MEDIUM | 6.5 | 0.5% | Dec 13, 2024 | The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to,... |
| CVE-2024-12414 | MEDIUM | 4.3 | 0.2% | Dec 13, 2024 | The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-12309 | MEDIUM | 5.3 | 0.3% | Dec 13, 2024 | The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Referen... |
| CVE-2024-12042 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-11911 | MEDIUM | 4.3 | 0.3% | Dec 13, 2024 | The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability c... |
| CVE-2024-11910 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search blo... |
| CVE-2024-11832 | MEDIUM | 5.4 | 0.2% | Dec 13, 2024 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cu... |
| CVE-2024-11754 | MEDIUM | 6.4 | 0.3% | Dec 13, 2024 | The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trafftbook... |
| CVE-2024-11275 | MEDIUM | 4.3 | 0.3% | Dec 13, 2024 | The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable... |
| CVE-2024-55918 | MEDIUM | 5.3 | 0.5% | Dec 13, 2024 | An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules... |
| CVE-2024-12581 | MEDIUM | 4.8 | 0.5% | Dec 13, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-11839 | HIGH | 7.5 | 0.3% | Dec 13, 2024 | Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitra... |
| CVE-2024-11838 | CRITICAL | 9.8 | 0.4% | Dec 13, 2024 | External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocument... |
| CVE-2024-11837 | CRITICAL | 9.8 | 0.5% | Dec 13, 2024 | Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac allows... |
| CVE-2024-11836 | HIGH | 7.5 | 0.3% | Dec 13, 2024 | Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue a... |
| CVE-2024-11835 | HIGH | 7.5 | 0.4% | Dec 13, 2024 | Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.... |
| CVE-2024-11834 | CRITICAL | 9.1 | 0.5% | Dec 13, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrar... |
| CVE-2024-11833 | CRITICAL | 9.1 | 0.5% | Dec 13, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrar... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now