2024 CVE Vulnerabilities
39,233 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49646 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ioannup Code Gener... |
| CVE-2024-10181 | MEDIUM | 6.4 | 0.4% | Oct 29, 2024 | The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's newsletters_video sho... |
| CVE-2024-50410 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Namaste! LMS n... |
| CVE-2024-50409 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Namaste! LMS n... |
| CVE-2024-50407 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Namaste! LMS n... |
| CVE-2024-49692 | MEDIUM | 5.4 | 0.2% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCenter Affiliate... |
| CVE-2024-49679 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpkoithemes WPKoi ... |
| CVE-2024-49678 | HIGH | 7.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jinwen js a... |
| CVE-2024-49673 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Van Abel LaTeX2HTM... |
| CVE-2024-49672 | MEDIUM | 6.1 | 0.2% | Oct 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in giffordcheung Google Docs RSVP google-docs-rsvp-guestlist allows Stor... |
| CVE-2024-49670 | MEDIUM | 6.1 | 0.3% | Oct 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sam Glover Client ... |
| CVE-2024-10360 | MEDIUM | 4.3 | 0.4% | Oct 29, 2024 | The Move Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to... |
| CVE-2024-10266 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Vide... |
| CVE-2024-10233 | MEDIUM | 5.4 | 0.3% | Oct 29, 2024 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2024-10185 | MEDIUM | 6.4 | 0.4% | Oct 29, 2024 | The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2024-10184 | MEDIUM | 6.4 | 0.4% | Oct 29, 2024 | The StreamWeasels Kick Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw... |
| CVE-2024-9376 | MEDIUM | 6.4 | 0.4% | Oct 29, 2024 | The Kata Plus – Addons for Elementor – Widgets, Extensions and Templates plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-50550 | CRITICAL | 9.8 | 0.9% | Oct 29, 2024 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Privilege ... |
| CVE-2024-10437 | MEDIUM | 4.3 | 0.4% | Oct 29, 2024 | The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to unauthorized Smar Message activation/deacti... |
| CVE-2024-10436 | HIGH | 8.8 | 0.7% | Oct 29, 2024 | The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,... |
| CVE-2024-10227 | MEDIUM | 6.4 | 0.3% | Oct 29, 2024 | The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atkp_product sh... |
| CVE-2024-9438 | MEDIUM | 6.1 | 0.4% | Oct 29, 2024 | The SEUR Oficial plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'change_service' parameter... |
| CVE-2024-50490 | CRITICAL | 9.8 | 1.0% | Oct 29, 2024 | Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained... |
| CVE-2024-50485 | CRITICAL | 9.8 | 1.0% | Oct 29, 2024 | Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issu... |
| CVE-2024-50481 | HIGH | 8.8 | 0.4% | Oct 29, 2024 | Incorrect Privilege Assignment vulnerability in stackthemes Bstone Demo Importer bstone-demo-importer allows Privilege E... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now