2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49231 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cyclop WordPress V... |
| CVE-2024-49230 | MEDIUM | 6.1 | 0.3% | Oct 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harry005 Ajax Cust... |
| CVE-2024-49228 | MEDIUM | 5.4 | 0.2% | Oct 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edwin Rivera bVers... |
| CVE-2024-49225 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in swebdeveloper wpPr... |
| CVE-2024-49224 | MEDIUM | 6.1 | 0.3% | Oct 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mahesh_9696 Mitm B... |
| CVE-2024-10057 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rfw-youtube-video... |
| CVE-2024-4740 | HIGH | 7.5 | 0.3% | Oct 18, 2024 | MXsecurity software versions v1.1.0 and prior are vulnerable because of the use of hard-coded credentials. This vulnerab... |
| CVE-2024-4739 | HIGH | 7.5 | 0.3% | Oct 18, 2024 | The lack of access restriction to a resource from unauthorized users makes MXsecurity software versions v1.1.0 and prior... |
| CVE-2024-47487 | HIGH | 8.8 | 0.4% | Oct 18, 2024 | There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user ... |
| CVE-2024-47486 | MEDIUM | 6.1 | 0.3% | Oct 18, 2024 | There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts in... |
| CVE-2024-47485 | CRITICAL | 9.8 | 0.5% | Oct 18, 2024 | There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build ma... |
| CVE-2024-10080 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | The WP Easy Post Types plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to... |
| CVE-2024-10079 | HIGH | 8.8 | 0.8% | Oct 18, 2024 | The WP Easy Post Types plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.... |
| CVE-2024-10078 | MEDIUM | 6.3 | 0.4% | Oct 18, 2024 | The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to ... |
| CVE-2024-10055 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2024-9703 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' short... |
| CVE-2024-9206 | MEDIUM | 6.1 | 0.4% | Oct 18, 2024 | The MAS Companies For WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use... |
| CVE-2024-47793 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | Stored cross-site scripting vulnerability exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. When acces... |
| CVE-2024-46897 | LOW | 3.8 | 0.4% | Oct 18, 2024 | Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and e... |
| CVE-2024-38820 | MEDIUM | 5.3 | 0.6% | Oct 18, 2024 | The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() ... |
| CVE-2024-9892 | MEDIUM | 4.8 | 0.3% | Oct 18, 2024 | The Add Widget After Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all... |
| CVE-2024-9848 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | The Product Customizer Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a... |
| CVE-2024-9452 | MEDIUM | 5.4 | 0.3% | Oct 18, 2024 | The Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t... |
| CVE-2024-9383 | MEDIUM | 6.1 | 0.4% | Oct 18, 2024 | The Parcel Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all ve... |
| CVE-2024-9382 | MEDIUM | 6.1 | 0.3% | Oct 18, 2024 | The Gantry 4 Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'override_id' parame... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now