2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51615 | CRITICAL | 9.3 | 0.4% | Dec 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Marka WordPress... |
| CVE-2024-4633 | MEDIUM | 6.4 | 0.4% | Dec 6, 2024 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ad... |
| CVE-2024-21571 | HIGH | 8.1 | 0.2% | Dec 6, 2024 | Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables... |
| CVE-2024-11321 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Hi e-learni... |
| CVE-2024-10516 | HIGH | 8.1 | 6.5% | Dec 6, 2024 | The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and inc... |
| CVE-2024-11022 | MEDIUM | 5.6 | 0.4% | Dec 6, 2024 | The authentication process to the web server uses a challenge response procedure which inludes the nonce and additional ... |
| CVE-2024-10776 | HIGH | 8.2 | 0.5% | Dec 6, 2024 | Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an att... |
| CVE-2024-10774 | HIGH | 7.3 | 0.4% | Dec 6, 2024 | Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web... |
| CVE-2024-10773 | CRITICAL | 9 | 0.6% | Dec 6, 2024 | The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This... |
| CVE-2024-10772 | HIGH | 8.8 | 0.3% | Dec 6, 2024 | Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high imp... |
| CVE-2024-10771 | HIGH | 8.8 | 1.1% | Dec 6, 2024 | Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code... |
| CVE-2024-53908 | CRITICAL | 9.8 | 1.4% | Dec 6, 2024 | An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django... |
| CVE-2024-53907 | HIGH | 7.5 | 1.4% | Dec 6, 2024 | An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method an... |
| CVE-2024-11730 | MEDIUM | 6.5 | 0.4% | Dec 6, 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sor... |
| CVE-2024-11729 | MEDIUM | 6.5 | 0.6% | Dec 6, 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'ser... |
| CVE-2024-53142 | HIGH | 7.8 | 0.2% | Dec 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: initramfs: avoid filename buffer overrun The initr... |
| CVE-2024-53141 | HIGH | 7.8 | 0.4% | Dec 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap... |
| CVE-2024-11728 | HIGH | 7.5 | 13.3% | Dec 6, 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'vis... |
| CVE-2024-11460 | HIGH | 7.5 | 0.5% | Dec 6, 2024 | The Verowa Connect plugin for WordPress is vulnerable to SQL Injection via the 'search_string' parameter in all versions... |
| CVE-2024-11289 | HIGH | 8.1 | 0.7% | Dec 6, 2024 | The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via se... |
| CVE-2024-10909 | MEDIUM | 6.3 | 0.4% | Dec 6, 2024 | The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX a... |
| CVE-2024-10681 | MEDIUM | 6.3 | 0.4% | Dec 6, 2024 | The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPres... |
| CVE-2024-9872 | MEDIUM | 5.4 | 0.2% | Dec 6, 2024 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2024-9866 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' p... |
| CVE-2024-9706 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now