2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56451 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this... |
| CVE-2024-56450 | MEDIUM | 5.5 | 0.1% | Jan 8, 2025 | Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may a... |
| CVE-2024-12713 | MEDIUM | 5.3 | 0.3% | Jan 8, 2025 | The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in a... |
| CVE-2024-12521 | MEDIUM | 6.4 | 0.3% | Jan 8, 2025 | The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti-embed-g... |
| CVE-2024-12112 | MEDIUM | 6.4 | 0.2% | Jan 8, 2025 | The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder ... |
| CVE-2024-11916 | MEDIUM | 5.4 | 0.2% | Jan 8, 2025 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and ret... |
| CVE-2024-56445 | MEDIUM | 5.3 | 0.3% | Jan 8, 2025 | Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulner... |
| CVE-2024-56441 | MEDIUM | 5.9 | 0.1% | Jan 8, 2025 | Race condition vulnerability in the Bastet module Impact: Successful exploitation of this vulnerability may affect servi... |
| CVE-2024-54120 | MEDIUM | 5.9 | 0.1% | Jan 8, 2025 | Race condition vulnerability in the distributed notification module Impact: Successful exploitation of this vulnerabilit... |
| CVE-2024-47934 | MEDIUM | 6.9 | 0.4% | Jan 8, 2025 | Improper Input Validation vulnerability in Management Program in TXOne Networks Portable Inspector and Portable Inspecto... |
| CVE-2024-47239 | MEDIUM | 6.5 | 0.4% | Jan 8, 2025 | Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A rem... |
| CVE-2024-40679 | MEDIUM | 5.5 | 0.2% | Jan 8, 2025 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulner... |
| CVE-2024-55218 | MEDIUM | 6.1 | 0.7% | Jan 7, 2025 | IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter. |
| CVE-2024-50659 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privile... |
| CVE-2024-44450 | MEDIUM | 5.4 | 0.4% | Jan 7, 2025 | Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190. |
| CVE-2024-56272 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-rol... |
| CVE-2024-56270 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Retrieve Embedded Sensitive Data... |
| CVE-2024-40747 | MEDIUM | 6.1 | 0.2% | Jan 7, 2025 | Various module chromes didn't properly process inputs, leading to XSS vectors. |
| CVE-2024-12429 | MEDIUM | 5.1 | 0.3% | Jan 7, 2025 | An attacker who successfully exploited these vulnerabilities could grant read access to files. A vulnerability exists in... |
| CVE-2024-52813 | MEDIUM | 4.3 | 0.5% | Jan 7, 2025 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust c... |
| CVE-2024-28778 | MEDIUM | 6.5 | 0.5% | Jan 7, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys.... |
| CVE-2024-25037 | MEDIUM | 4.3 | 0.5% | Jan 7, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive ... |
| CVE-2024-11681 | MEDIUM | 6.9 | 0.5% | Jan 7, 2025 | A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running por... |
| CVE-2024-45640 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against... |
| CVE-2024-45100 | MEDIUM | 4.9 | 0.5% | Jan 7, 2025 | IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration r... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now