2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10939 | MEDIUM | 4.8 | 0.3% | Dec 13, 2024 | The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which co... |
| CVE-2024-10678 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputt... |
| CVE-2024-21544 | HIGH | 8.6 | 0.6% | Dec 13, 2024 | Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL ... |
| CVE-2024-21543 | HIGH | 7.1 | 0.5% | Dec 13, 2024 | Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fai... |
| CVE-2024-12579 | MEDIUM | 5.3 | 0.3% | Dec 13, 2024 | The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to... |
| CVE-2024-12574 | MEDIUM | 5.4 | 0.3% | Dec 13, 2024 | The SVG Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions... |
| CVE-2024-11809 | MEDIUM | 6.1 | 0.3% | Dec 13, 2024 | The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'img_src'... |
| CVE-2024-11767 | MEDIUM | 6.4 | 0.3% | Dec 13, 2024 | The NewsmanApp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'newsman_subscribe_wid... |
| CVE-2024-12572 | MEDIUM | 6.1 | 0.2% | Dec 13, 2024 | The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-12300 | LOW | 3.7 | 0.4% | Dec 13, 2024 | The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing ca... |
| CVE-2024-12603 | CRITICAL | 9.8 | 0.5% | Dec 13, 2024 | A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application passwo... |
| CVE-2024-9508 | HIGH | 8.5 | 0.2% | Dec 13, 2024 | Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose informat... |
| CVE-2024-12212 | HIGH | 8.5 | 0.2% | Dec 13, 2024 | The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supp... |
| CVE-2024-12289 | MEDIUM | 5.9 | 0.4% | Dec 12, 2024 | Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initializati... |
| CVE-2024-55888 | HIGH | 7.1 | 0.3% | Dec 12, 2024 | Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the p... |
| CVE-2024-55886 | MEDIUM | 6.9 | 0.3% | Dec 12, 2024 | OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes... |
| CVE-2024-55885 | HIGH | 7.5 | 0.3% | Dec 12, 2024 | beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a has... |
| CVE-2024-55879 | HIGH | 8.8 | 1.0% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with ... |
| CVE-2024-55878 | MEDIUM | 6.8 | 0.4% | Dec 12, 2024 | SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to ve... |
| CVE-2024-55877 | HIGH | 8.8 | 1.6% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5... |
| CVE-2024-55876 | MEDIUM | 5.4 | 0.6% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0,... |
| CVE-2024-55875 | CRITICAL | 9.8 | 1.9% | Dec 12, 2024 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML Ex... |
| CVE-2024-55663 | CRITICAL | 9.8 | 0.7% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc... |
| CVE-2024-54811 | CRITICAL | 9.8 | 0.6% | Dec 12, 2024 | A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to ex... |
| CVE-2024-49147 | CRITICAL | 9.8 | 1.3% | Dec 12, 2024 | Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now