2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9851 | MEDIUM | 5.4 | 0.4% | Nov 21, 2024 | The LSX Tour Operator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers... |
| CVE-2024-9828 | MEDIUM | 4.1 | 0.5% | Nov 21, 2024 | The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it... |
| CVE-2024-9768 | MEDIUM | 4.8 | 0.4% | Nov 21, 2024 | The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-9600 | MEDIUM | 4.8 | 0.4% | Nov 21, 2024 | The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-9542 | MEDIUM | 4.3 | 0.3% | Nov 21, 2024 | The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,... |
| CVE-2024-9442 | MEDIUM | 5.4 | 0.4% | Nov 21, 2024 | The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2024-9371 | MEDIUM | 6.1 | 0.5% | Nov 21, 2024 | The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-... |
| CVE-2024-9111 | MEDIUM | 6.4 | 0.5% | Nov 21, 2024 | The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi... |
| CVE-2024-8157 | MEDIUM | 4.3 | 0.2% | Nov 21, 2024 | The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which... |
| CVE-2024-7517 | HIGH | 7.8 | 0.6% | Nov 21, 2024 | A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms... |
| CVE-2024-5029 | MEDIUM | 4.8 | 0.2% | Nov 21, 2024 | The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is miss... |
| CVE-2024-52797 | HIGH | 7.5 | 0.9% | Nov 21, 2024 | Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and... |
| CVE-2024-52067 | MEDIUM | 4.9 | 0.7% | Nov 21, 2024 | Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context valu... |
| CVE-2024-45663 | HIGH | 7.5 | 0.7% | Nov 21, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of serv... |
| CVE-2024-30896 | CRITICAL | 9.1 | 5.2% | Nov 21, 2024 | InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut... |
| CVE-2024-11596 | MEDIUM | 5.5 | 0.3% | Nov 21, 2024 | ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or cra... |
| CVE-2024-11595 | MEDIUM | 5.5 | 0.3% | Nov 21, 2024 | FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet in... |
| CVE-2024-11456 | MEDIUM | 6.1 | 0.4% | Nov 21, 2024 | The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2024-11455 | MEDIUM | 6.4 | 0.4% | Nov 21, 2024 | The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-ma... |
| CVE-2024-11447 | MEDIUM | 6.1 | 0.5% | Nov 21, 2024 | The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-11440 | MEDIUM | 6.4 | 0.5% | Nov 21, 2024 | The Grey Owl Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gol_button' sh... |
| CVE-2024-11438 | MEDIUM | 6.4 | 0.4% | Nov 21, 2024 | The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '... |
| CVE-2024-11435 | MEDIUM | 6.1 | 0.5% | Nov 21, 2024 | The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter... |
| CVE-2024-11432 | MEDIUM | 6.4 | 1.2% | Nov 21, 2024 | The SuevaFree Essential Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'counter'... |
| CVE-2024-11428 | MEDIUM | 6.4 | 1.1% | Nov 21, 2024 | The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now