2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10847 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all version... |
| CVE-2024-13466 | MEDIUM | 6.4 | 0.3% | Jan 30, 2025 | The Automatically Hierarchic Categories in Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2024-13380 | MEDIUM | 6.4 | 0.3% | Jan 30, 2025 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2024-13706 | MEDIUM | 6.1 | 0.3% | Jan 30, 2025 | The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in a... |
| CVE-2024-12524 | MEDIUM | 6.4 | 0.3% | Jan 30, 2025 | The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-lo... |
| CVE-2024-12409 | MEDIUM | 6.1 | 0.3% | Jan 30, 2025 | The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all... |
| CVE-2024-13758 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ... |
| CVE-2024-13732 | MEDIUM | 5.4 | 0.4% | Jan 30, 2025 | The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-13470 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-13642 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image... |
| CVE-2024-13457 | MEDIUM | 5.3 | 0.3% | Jan 30, 2025 | The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version... |
| CVE-2024-12921 | MEDIUM | 6.4 | 0.2% | Jan 30, 2025 | The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcod... |
| CVE-2024-12709 | MEDIUM | 4.3 | 0.2% | Jan 30, 2025 | The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to m... |
| CVE-2024-12163 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The goodlayers-core WordPress plugin before 2.1.3 allows users with a subscriber role and above to upload SVGs containin... |
| CVE-2024-10309 | MEDIUM | 5.9 | 0.3% | Jan 30, 2025 | The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when o... |
| CVE-2024-57513 | MEDIUM | 6.5 | 0.3% | Jan 29, 2025 | A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4. |
| CVE-2024-51182 | MEDIUM | 6.1 | 0.3% | Jan 29, 2025 | HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML c... |
| CVE-2024-57439 | MEDIUM | 4.9 | 0.6% | Jan 29, 2025 | An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Ser... |
| CVE-2024-57438 | MEDIUM | 5.4 | 0.3% | Jan 29, 2025 | Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves highe... |
| CVE-2024-57437 | MEDIUM | 6.5 | 0.5% | Jan 29, 2025 | RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list. |
| CVE-2024-41140 | MEDIUM | 6.5 | 0.9% | Jan 29, 2025 | Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in th... |
| CVE-2024-13561 | MEDIUM | 6.4 | 0.3% | Jan 29, 2025 | The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_ov... |
| CVE-2024-57514 | MEDIUM | 4.8 | 0.9% | Jan 28, 2025 | The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listi... |
| CVE-2024-29869 | MEDIUM | 5.5 | 0.3% | Jan 28, 2025 | Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the fil... |
| CVE-2024-40674 | MEDIUM | 5.3 | 0.2% | Jan 28, 2025 | In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now