2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11143 | MEDIUM | 4.3 | 0.2% | Nov 13, 2024 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ... |
| CVE-2024-10882 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du... |
| CVE-2024-10684 | MEDIUM | 6.1 | 0.4% | Nov 13, 2024 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' p... |
| CVE-2024-10593 | MEDIUM | 4.3 | 0.3% | Nov 13, 2024 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu... |
| CVE-2024-10531 | MEDIUM | 4.3 | 0.5% | Nov 13, 2024 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-10530 | MEDIUM | 4.3 | 0.4% | Nov 13, 2024 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-10529 | MEDIUM | 5.3 | 0.5% | Nov 13, 2024 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-9614 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ... |
| CVE-2024-9578 | MEDIUM | 5.3 | 0.5% | Nov 13, 2024 | The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked t... |
| CVE-2024-9426 | MEDIUM | 6.4 | 0.3% | Nov 13, 2024 | The Aqua SVG Sprite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio... |
| CVE-2024-8985 | MEDIUM | 6.4 | 0.4% | Nov 13, 2024 | The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2024-8874 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scr... |
| CVE-2024-39712 | CRITICAL | 9.1 | 1.7% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version... |
| CVE-2024-39711 | CRITICAL | 9.1 | 1.7% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version... |
| CVE-2024-39710 | CRITICAL | 9.1 | 1.9% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version... |
| CVE-2024-39709 | HIGH | 7.8 | 0.3% | Nov 13, 2024 | Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Se... |
| CVE-2024-38656 | CRITICAL | 9.1 | 1.7% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version... |
| CVE-2024-38655 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version... |
| CVE-2024-38654 | MEDIUM | 4.4 | 0.3% | Nov 13, 2024 | Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with... |
| CVE-2024-38649 | HIGH | 7.5 | 1.9% | Nov 13, 2024 | An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remot... |
| CVE-2024-37400 | HIGH | 7.5 | 2.0% | Nov 13, 2024 | An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigg... |
| CVE-2024-37398 | HIGH | 7.8 | 0.3% | Nov 13, 2024 | Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate t... |
| CVE-2024-37376 | HIGH | 7.2 | 3.1% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-34787 | HIGH | 7.8 | 17.9% | Nov 13, 2024 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo... |
| CVE-2024-34784 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now