2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7386 | MEDIUM | 4.3 | 0.2% | Sep 25, 2024 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2024-6590 | MEDIUM | 4.3 | 0.3% | Sep 25, 2024 | The Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Disp... |
| CVE-2024-9148 | MEDIUM | 6.1 | 0.6% | Sep 25, 2024 | Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed... |
| CVE-2024-9141 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaSc... |
| CVE-2024-8941 | MEDIUM | 5.3 | 0.6% | Sep 25, 2024 | Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “su... |
| CVE-2024-8919 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti... |
| CVE-2024-8917 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ... |
| CVE-2024-8801 | MEDIUM | 4.3 | 0.4% | Sep 25, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t... |
| CVE-2024-8437 | MEDIUM | 4.3 | 0.3% | Sep 25, 2024 | The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missin... |
| CVE-2024-8291 | MEDIUM | 4.8 | 0.5% | Sep 25, 2024 | Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A ... |
| CVE-2024-8267 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable ... |
| CVE-2024-8103 | MEDIUM | 5.4 | 0.3% | Sep 25, 2024 | The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in ... |
| CVE-2024-8067 | MEDIUM | 5.8 | 0.2% | Sep 25, 2024 | In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument inject... |
| CVE-2024-7398 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addit... |
| CVE-2024-47048 | MEDIUM | 5.4 | 0.4% | Sep 25, 2024 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release no... |
| CVE-2024-46934 | MEDIUM | 6.1 | 0.3% | Sep 25, 2024 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XS... |
| CVE-2024-41725 | MEDIUM | 6.1 | 0.4% | Sep 25, 2024 | ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may ... |
| CVE-2024-38324 | MEDIUM | 6.5 | 0.3% | Sep 25, 2024 | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registrati... |
| CVE-2024-8794 | MEDIUM | 5.3 | 0.4% | Sep 24, 2024 | The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and includi... |
| CVE-2024-8628 | MEDIUM | 5.4 | 0.3% | Sep 24, 2024 | The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable ... |
| CVE-2024-8738 | MEDIUM | 6.1 | 0.4% | Sep 24, 2024 | The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu... |
| CVE-2024-8716 | MEDIUM | 6.1 | 0.4% | Sep 24, 2024 | The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ... |
| CVE-2024-8662 | MEDIUM | 6.1 | 0.4% | Sep 24, 2024 | The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ... |
| CVE-2024-8657 | MEDIUM | 5.4 | 0.4% | Sep 24, 2024 | The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortc... |
| CVE-2024-8544 | MEDIUM | 6.1 | 0.5% | Sep 24, 2024 | The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now