2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11585 | HIGH | 7.5 | 0.6% | Dec 6, 2024 | The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing ... |
| CVE-2024-11201 | MEDIUM | 6.4 | 0.8% | Dec 6, 2024 | The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo... |
| CVE-2024-10578 | HIGH | 8.8 | 1.3% | Dec 6, 2024 | The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability ... |
| CVE-2024-10551 | MEDIUM | 4.8 | 0.3% | Dec 6, 2024 | The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-10480 | MEDIUM | 4.3 | 0.2% | Dec 6, 2024 | The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could a... |
| CVE-2024-11379 | MEDIUM | 6.1 | 0.3% | Dec 6, 2024 | The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all v... |
| CVE-2024-9769 | MEDIUM | 4.8 | 0.3% | Dec 6, 2024 | The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-10836 | MEDIUM | 6.1 | 0.4% | Dec 6, 2024 | The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions u... |
| CVE-2024-10247 | MEDIUM | 4.9 | 0.5% | Dec 6, 2024 | The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection... |
| CVE-2024-49041 | MEDIUM | 4.3 | 1.1% | Dec 6, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-11149 | MEDIUM | 5.5 | 0.1% | Dec 6, 2024 | In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs. |
| CVE-2024-6219 | LOW | 3.8 | 0.2% | Dec 6, 2024 | Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust... |
| CVE-2024-6156 | LOW | 3.8 | 0.2% | Dec 6, 2024 | Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was prese... |
| CVE-2024-52798 | HIGH | 7.7 | 0.8% | Dec 5, 2024 | path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular exp... |
| CVE-2024-38920 | CRITICAL | 9.1 | 0.5% | Dec 5, 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via... |
| CVE-2024-38910 | HIGH | 7.5 | 0.5% | Dec 5, 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in th... |
| CVE-2024-37863 | CRITICAL | 9.8 | 0.6% | Dec 5, 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow vi... |
| CVE-2024-37862 | HIGH | 7.3 | 0.3% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-hum... |
| CVE-2024-37861 | CRITICAL | 9.8 | 0.6% | Dec 5, 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow vi... |
| CVE-2024-37860 | HIGH | 7.3 | 0.3% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allo... |
| CVE-2024-30964 | HIGH | 7.8 | 0.2% | Dec 5, 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navig... |
| CVE-2024-30963 | HIGH | 7.8 | 0.2% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation... |
| CVE-2024-30962 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation... |
| CVE-2024-30961 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navig... |
| CVE-2024-54140 | LOW | 2.1 | 0.2% | Dec 5, 2024 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now