2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54232 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RRDevs RRAddons fo... |
| CVE-2024-54230 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Masud Hasan Unlock... |
| CVE-2024-54228 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technolo... |
| CVE-2024-54227 | MEDIUM | 4.3 | 0.4% | Dec 9, 2024 | Missing Authorization vulnerability in Dotstore Minimum and Maximum Quantity for WooCommerce min-and-max-quantity-for-wo... |
| CVE-2024-54226 | HIGH | 7.1 | 0.2% | Dec 9, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This ... |
| CVE-2024-54225 | HIGH | 7.5 | 0.8% | Dec 9, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-54224 | MEDIUM | 5.4 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quomodosoft Elemen... |
| CVE-2024-54223 | MEDIUM | 6.1 | 0.3% | Dec 9, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in reputeinfosystems ARForms... |
| CVE-2024-54220 | HIGH | 7.1 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Servic... |
| CVE-2024-54219 | HIGH | 7.1 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thehp AIO Contact ... |
| CVE-2024-54217 | MEDIUM | 5.4 | 0.4% | Dec 9, 2024 | Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <=... |
| CVE-2024-54215 | CRITICAL | 9.3 | 0.6% | Dec 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy revy.... |
| CVE-2024-53822 | CRITICAL | 10 | 0.7% | Dec 9, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Re... |
| CVE-2024-53819 | MEDIUM | 5.3 | 0.5% | Dec 9, 2024 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects C... |
| CVE-2024-53818 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultima... |
| CVE-2024-53816 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons.This issue affects ... |
| CVE-2024-53798 | MEDIUM | 5.4 | 0.3% | Dec 9, 2024 | Missing Authorization vulnerability in BAKKBONE Australia FloristPress bakkbone-florist-companion.This issue affects Flo... |
| CVE-2024-53791 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ogun Labs Lenxel C... |
| CVE-2024-53790 | HIGH | 7.5 | 0.7% | Dec 9, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ogun Labs Lenxel Core fo... |
| CVE-2024-53785 | MEDIUM | 4.3 | 0.4% | Dec 9, 2024 | Missing Authorization vulnerability in Alexander Volkov Chatter.This issue affects Chatter: from n/a through 1.0.1. |
| CVE-2024-43222 | CRITICAL | 9.8 | 0.7% | Dec 9, 2024 | Missing Authorization vulnerability in SeventhQueen Sweet Date sweetdate allows Privilege Escalation.This issue affects ... |
| CVE-2024-46901 | MEDIUM | 4.3 | 1.9% | Dec 9, 2024 | Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn... |
| CVE-2024-12307 | MEDIUM | 4.3 | 0.2% | Dec 9, 2024 | A function-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows te... |
| CVE-2024-12306 | MEDIUM | 4.3 | 0.2% | Dec 9, 2024 | Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthori... |
| CVE-2024-12305 | MEDIUM | 4.3 | 0.2% | Dec 9, 2024 | An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows una... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now