2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11420 | MEDIUM | 5.4 | 0.2% | Dec 5, 2024 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter i... |
| CVE-2024-11341 | MEDIUM | 4.3 | 0.2% | Dec 5, 2024 | The Simple Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-11324 | MEDIUM | 6.1 | 0.3% | Dec 5, 2024 | The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad... |
| CVE-2024-10848 | MEDIUM | 6.4 | 0.2% | Dec 5, 2024 | The NewsMunch theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versi... |
| CVE-2024-10777 | MEDIUM | 4.3 | 0.3% | Dec 5, 2024 | The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ... |
| CVE-2024-10056 | MEDIUM | 6.4 | 0.3% | Dec 5, 2024 | The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's liv... |
| CVE-2024-10937 | MEDIUM | 5.3 | 0.3% | Dec 5, 2024 | The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i... |
| CVE-2024-11429 | HIGH | 8.8 | 0.7% | Dec 5, 2024 | The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress i... |
| CVE-2024-42195 | MEDIUM | 6.8 | 0.3% | Dec 5, 2024 | HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary H... |
| CVE-2024-10178 | MEDIUM | 5.4 | 0.3% | Dec 5, 2024 | The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-10881 | MEDIUM | 6.4 | 0.2% | Dec 5, 2024 | The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in... |
| CVE-2024-54014 | LOW | 3.6 | 0.2% | Dec 5, 2024 | Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skyla... |
| CVE-2024-12188 | CRITICAL | 9.8 | 0.7% | Dec 5, 2024 | A vulnerability was found in 1000 Projects Library Management System 1.0. It has been declared as critical. Affected by ... |
| CVE-2024-12187 | CRITICAL | 9.8 | 0.6% | Dec 5, 2024 | A vulnerability was found in 1000 Projects Library Management System 1.0. It has been classified as critical. Affected i... |
| CVE-2024-54221 | CRITICAL | 9.3 | 0.4% | Dec 5, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp FAT Servic... |
| CVE-2024-12186 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | A vulnerability was found in code-projects Hotel Management System 1.0 and classified as problematic. This issue affects... |
| CVE-2024-12185 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | A vulnerability has been found in code-projects Hotel Management System 1.0 and classified as problematic. This vulnerab... |
| CVE-2024-53982 | HIGH | 8.7 | 0.5% | Dec 4, 2024 | ZOO-Project is a C-based WPS (Web Processing Service) implementation. A path traversal vulnerability was discovered in Z... |
| CVE-2024-12183 | MEDIUM | 5.4 | 0.4% | Dec 4, 2024 | A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS ... |
| CVE-2024-12182 | MEDIUM | 5.4 | 0.4% | Dec 4, 2024 | A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some ... |
| CVE-2024-12181 | MEDIUM | 5.4 | 0.4% | Dec 4, 2024 | A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown fun... |
| CVE-2024-12180 | MEDIUM | 5.4 | 0.4% | Dec 4, 2024 | A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file... |
| CVE-2024-54675 | MEDIUM | 6.1 | 0.2% | Dec 4, 2024 | app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ... |
| CVE-2024-54674 | MEDIUM | 6.1 | 0.2% | Dec 4, 2024 | app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom cluste... |
| CVE-2024-51210 | MEDIUM | 5.3 | 0.5% | Dec 4, 2024 | Firepad through 1.5.11 allows remote attackers, who have knowledge of a pad ID, to retrieve both the current text of a d... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now