2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47629 | MEDIUM | 6.5 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate ... |
| CVE-2024-47628 | MEDIUM | 6.5 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studi... |
| CVE-2024-47627 | MEDIUM | 6.5 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Trave... |
| CVE-2024-47626 | MEDIUM | 6.5 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit r... |
| CVE-2024-47625 | MEDIUM | 5.4 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themelooks Enter A... |
| CVE-2024-47647 | MEDIUM | 5.9 | 0.3% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Essekia Helpie FAQ... |
| CVE-2024-47646 | MEDIUM | 4.7 | 0.3% | Oct 5, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in tomlister Payflex Payment Gateway payflex-payment-g... |
| CVE-2024-47643 | MEDIUM | 6.5 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Include Fussb... |
| CVE-2024-47642 | MEDIUM | 6.5 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Keap Keap Official... |
| CVE-2024-47639 | MEDIUM | 6.5 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vibhav Sinha VdoCi... |
| CVE-2024-47638 | MEDIUM | 6.1 | 0.3% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booki... |
| CVE-2024-47635 | MEDIUM | 5.4 | 0.2% | Oct 5, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in TinyPNG TinyPNG tiny-compress-images allows Cross Site Request Forger... |
| CVE-2024-47633 | MEDIUM | 6.5 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Zoho Fo... |
| CVE-2024-47632 | MEDIUM | 5.4 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit... |
| CVE-2024-47631 | MEDIUM | 6.5 | 0.2% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Logo Caro... |
| CVE-2024-47309 | MEDIUM | 6.6 | 0.6% | Oct 5, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Condless Cities Shipping... |
| CVE-2024-9161 | MEDIUM | 6.5 | 2.0% | Oct 5, 2024 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modificatio... |
| CVE-2024-9146 | MEDIUM | 4.9 | 0.6% | Oct 5, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in jamesdlow CSS JS Files c... |
| CVE-2024-9417 | MEDIUM | 6.1 | 0.3% | Oct 5, 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigur... |
| CVE-2024-8486 | MEDIUM | 5.4 | 0.4% | Oct 5, 2024 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-8743 | MEDIUM | 6.8 | 0.8% | Oct 5, 2024 | The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulner... |
| CVE-2024-9528 | MEDIUM | 4.8 | 0.4% | Oct 5, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-9455 | MEDIUM | 6.4 | 0.3% | Oct 5, 2024 | The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upload... |
| CVE-2024-9385 | MEDIUM | 6.1 | 0.4% | Oct 5, 2024 | The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg... |
| CVE-2024-47847 | MEDIUM | 6.1 | 0.4% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now