2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56195 | MEDIUM | 6.3 | 0.7% | Mar 6, 2025 | Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 th... |
| CVE-2024-38311 | MEDIUM | 6.3 | 0.8% | Mar 6, 2025 | Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 ... |
| CVE-2024-56202 | MEDIUM | 4.3 | 0.8% | Mar 6, 2025 | Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.... |
| CVE-2024-13902 | MEDIUM | 5.4 | 0.3% | Mar 6, 2025 | A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown ... |
| CVE-2024-13897 | MEDIUM | 6.5 | 0.9% | Mar 6, 2025 | The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val... |
| CVE-2024-13868 | MEDIUM | 6.1 | 0.3% | Mar 6, 2025 | The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise an... |
| CVE-2024-57174 | HIGH | 8.1 | 0.3% | Mar 5, 2025 | A misconfiguration in Alphion ASEE-1443 Firmware v0.4.H.00.02.15 defines a previously unregistered domain name as the de... |
| CVE-2024-51144 | HIGH | 8.8 | 0.4% | Mar 5, 2025 | Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_d... |
| CVE-2024-48246 | MEDIUM | 5.4 | 0.4% | Mar 5, 2025 | Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /veh... |
| CVE-2024-31525 | HIGH | 7.2 | 0.4% | Mar 5, 2025 | Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to eleva... |
| CVE-2024-53458 | HIGH | 7.5 | 0.5% | Mar 5, 2025 | Sysax Multi Server 6.99 is vulnerable to a denial of service (DoS) condition when processing specially crafted SSH packe... |
| CVE-2024-11035 | LOW | 2.5 | 0.1% | Mar 5, 2025 | Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a ty... |
| CVE-2024-12799 | CRITICAL | 10 | 0.4% | Mar 5, 2025 | Insufficiently Protected Credentials vulnerability in OpenText Identity Manager Advanced Edition on Windows, Linux, 64 b... |
| CVE-2024-13147 | CRITICAL | 9.8 | 0.4% | Mar 5, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Merkur Software B2... |
| CVE-2024-12097 | CRITICAL | 9.8 | 0.4% | Mar 5, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informat... |
| CVE-2024-11216 | HIGH | 7.6 | 0.3% | Mar 5, 2025 | Authorization Bypass Through User-Controlled Key, Exposure of Private Personal Information to an Unauthorized Actor vuln... |
| CVE-2024-13471 | HIGH | 7.5 | 0.5% | Mar 5, 2025 | The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2024-13423 | MEDIUM | 5.3 | 0.4% | Mar 5, 2025 | The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capabili... |
| CVE-2024-12650 | MEDIUM | 5.4 | 0.3% | Mar 5, 2025 | An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memo... |
| CVE-2024-12281 | CRITICAL | 9.8 | 0.4% | Mar 5, 2025 | The Homey theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.2. This is... |
| CVE-2024-11951 | CRITICAL | 9.8 | 0.4% | Mar 5, 2025 | The Homey Login Register plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including... |
| CVE-2024-11153 | MEDIUM | 5.3 | 0.4% | Mar 5, 2025 | The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin... |
| CVE-2024-5667 | MEDIUM | 6.4 | 0.3% | Mar 5, 2025 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js Ja... |
| CVE-2024-13839 | MEDIUM | 6.1 | 0.3% | Mar 5, 2025 | The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t... |
| CVE-2024-13815 | MEDIUM | 6.5 | 0.3% | Mar 5, 2025 | The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now