2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8430 | MEDIUM | 5.3 | 0.3% | Oct 1, 2024 | The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
| CVE-2024-8324 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all ver... |
| CVE-2024-8288 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to S... |
| CVE-2024-9304 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The LocateAndFilter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2024-9274 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The Elastik Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v... |
| CVE-2024-9272 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The R Animated Icon Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all... |
| CVE-2024-9269 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The Relogo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,... |
| CVE-2024-9267 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The Easy WordPress Subscribe – Optin Hound plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to t... |
| CVE-2024-9119 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The SVG Complete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ... |
| CVE-2024-8990 | MEDIUM | 6.4 | 0.4% | Oct 1, 2024 | The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_pos... |
| CVE-2024-8989 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress i... |
| CVE-2024-8728 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | The Easy Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ... |
| CVE-2024-8727 | MEDIUM | 6.1 | 0.3% | Oct 1, 2024 | The DK PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without ... |
| CVE-2024-8720 | MEDIUM | 6.4 | 0.3% | Oct 1, 2024 | The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2024-8718 | MEDIUM | 6.1 | 0.4% | Oct 1, 2024 | The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter i... |
| CVE-2024-8675 | MEDIUM | 4.3 | 0.3% | Oct 1, 2024 | The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2024-8632 | MEDIUM | 6.5 | 0.3% | Oct 1, 2024 | The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and mo... |
| CVE-2024-8107 | MEDIUM | 5.4 | 0.3% | Oct 1, 2024 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers... |
| CVE-2024-21531 | MEDIUM | 5.3 | 0.9% | Oct 1, 2024 | All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigat... |
| CVE-2024-0116 | MEDIUM | 6.5 | 0.4% | Oct 1, 2024 | NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing ... |
| CVE-2024-9358 | MEDIUM | 5.9 | 0.7% | Oct 1, 2024 | A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability ... |
| CVE-2024-47396 | MEDIUM | 5.4 | 0.3% | Oct 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Ad... |
| CVE-2024-45073 | MEDIUM | 4.8 | 0.2% | Sep 30, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p... |
| CVE-2024-28807 | MEDIUM | 6.5 | 0.1% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @C... |
| CVE-2024-28810 | MEDIUM | 6.6 | 0.2% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now