2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50516 | MEDIUM | 5.9 | 0.4% | Nov 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamskaat Countdow... |
| CVE-2024-50515 | MEDIUM | 4.8 | 0.4% | Nov 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevin Stover Ninja... |
| CVE-2024-50514 | MEDIUM | 4.8 | 0.4% | Nov 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevin Stover Ninja... |
| CVE-2024-50513 | MEDIUM | 5.9 | 0.4% | Nov 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultima... |
| CVE-2024-50417 | HIGH | 8.8 | 1.9% | Nov 19, 2024 | Missing Authorization vulnerability in boldthemes Bold Page Builder bold-page-builder allows Exploiting Incorrectly Conf... |
| CVE-2024-49697 | MEDIUM | 4.3 | 0.4% | Nov 19, 2024 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incor... |
| CVE-2024-49689 | MEDIUM | 5.4 | 0.5% | Nov 19, 2024 | Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light hd-quiz-save-results-light allows Ex... |
| CVE-2024-49680 | MEDIUM | 4.3 | 0.4% | Nov 19, 2024 | Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2024-48071 | MEDIUM | 6.5 | 0.8% | Nov 19, 2024 | E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server direct... |
| CVE-2024-43338 | MEDIUM | 4.3 | 0.2% | Nov 19, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic Crowdsignal Dashboard – Polls, Surveys & more polldaddy al... |
| CVE-2024-52582 | MEDIUM | 4.7 | 0.2% | Nov 19, 2024 | Cachi2 is a command-line interface tool that pre-fetches a project's dependencies to aid in making the project's build p... |
| CVE-2024-50803 | MEDIUM | 5.4 | 0.5% | Nov 19, 2024 | The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allow... |
| CVE-2024-10524 | MEDIUM | 6.5 | 1.1% | Nov 19, 2024 | Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the U... |
| CVE-2024-52711 | MEDIUM | 5.7 | 0.6% | Nov 19, 2024 | DI-8100 v16.07.26A1 is vulnerable to Buffer Overflow In the ip_position_asp function via the ip parameter. |
| CVE-2024-11075 | HIGH | 8.8 | 0.2% | Nov 19, 2024 | A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local ... |
| CVE-2024-10204 | HIGH | 7.8 | 0.2% | Nov 19, 2024 | Heap-based Buffer Overflow and Uninitialized Variable vulnerabilities exist in the X_B and SAT file reading procedure in... |
| CVE-2024-9830 | MEDIUM | 6.1 | 0.4% | Nov 19, 2024 | The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without app... |
| CVE-2024-9777 | MEDIUM | 6.1 | 0.4% | Nov 19, 2024 | The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without app... |
| CVE-2024-52675 | CRITICAL | 9.8 | 0.5% | Nov 19, 2024 | SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php. |
| CVE-2024-11224 | MEDIUM | 6.4 | 0.4% | Nov 19, 2024 | The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘position’ parameter in all... |
| CVE-2024-11198 | MEDIUM | 6.4 | 0.4% | Nov 19, 2024 | The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter i... |
| CVE-2024-11194 | HIGH | 8.8 | 0.5% | Nov 19, 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized m... |
| CVE-2024-11195 | MEDIUM | 6.4 | 0.4% | Nov 19, 2024 | The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_em... |
| CVE-2024-11038 | HIGH | 7.3 | 0.6% | Nov 19, 2024 | The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress... |
| CVE-2024-11036 | CRITICAL | 9.8 | 0.7% | Nov 19, 2024 | The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for Wo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now