2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11957 | CRITICAL | 9.3 | 0.1% | Mar 4, 2025 | Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12... |
| CVE-2024-9149 | HIGH | 8.6 | 0.3% | Mar 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Comme... |
| CVE-2024-50706 | CRITICAL | 9.8 | 0.5% | Mar 4, 2025 | Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbi... |
| CVE-2024-50705 | HIGH | 7.1 | 0.2% | Mar 4, 2025 | Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote at... |
| CVE-2024-9618 | MEDIUM | 5.4 | 0.3% | Mar 4, 2025 | The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ... |
| CVE-2024-13724 | MEDIUM | 4.3 | 0.2% | Mar 4, 2025 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for Wor... |
| CVE-2024-13682 | MEDIUM | 4.3 | 0.1% | Mar 4, 2025 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for Wor... |
| CVE-2024-58050 | MEDIUM | 5.5 | 0.1% | Mar 4, 2025 | Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may ... |
| CVE-2024-58049 | MEDIUM | 5.5 | 0.1% | Mar 4, 2025 | Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability ... |
| CVE-2024-58048 | MEDIUM | 4.7 | 0.1% | Mar 4, 2025 | Multi-thread problem vulnerability in the package management module Impact: Successful exploitation of this vulnerabilit... |
| CVE-2024-58047 | MEDIUM | 5.5 | 0.1% | Mar 4, 2025 | Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability ... |
| CVE-2024-58046 | MEDIUM | 5.5 | 0.1% | Mar 4, 2025 | Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may ... |
| CVE-2024-58045 | MEDIUM | 4.7 | 0.1% | Mar 4, 2025 | Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this... |
| CVE-2024-58044 | MEDIUM | 5.5 | 0.1% | Mar 4, 2025 | Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerab... |
| CVE-2024-58043 | MEDIUM | 5.5 | 0.1% | Mar 4, 2025 | Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect se... |
| CVE-2024-48248 | HIGH | 8.6 | 94.0% | Mar 4, 2025 | NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /... |
| CVE-2024-47262 | MEDIUM | 5.3 | 0.3% | Mar 4, 2025 | Dzmitry Lukyanenka, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API param.cgi was vulnerable to a... |
| CVE-2024-47260 | MEDIUM | 6.5 | 0.4% | Mar 4, 2025 | 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API mediaclip.cgi did not have a sufficient ... |
| CVE-2024-47259 | HIGH | 7.1 | 0.5% | Mar 4, 2025 | Girishunawane, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi did not have a ... |
| CVE-2024-13685 | MEDIUM | 5.3 | 0.3% | Mar 4, 2025 | The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 retrieves client IP addresses from potentially untr... |
| CVE-2024-13686 | MEDIUM | 4.3 | 0.3% | Mar 4, 2025 | The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2024-55064 | MEDIUM | 5.4 | 0.2% | Mar 3, 2025 | Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject ar... |
| CVE-2024-5888 | MEDIUM | 4.8 | 0.2% | Mar 3, 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and below that may allow a remot... |
| CVE-2024-51966 | MEDIUM | 4.9 | 0.6% | Mar 3, 2025 | There is a path traversal vulnerability in ESRI ArcGIS Server versions 11.3 and below. Successful exploitation may allo... |
| CVE-2024-51963 | MEDIUM | 4.8 | 0.2% | Mar 3, 2025 | There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 11.3 and follow that may allow a remo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now