2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43051 | MEDIUM | 5.5 | 0.1% | Mar 3, 2025 | Information disclosure while deriving keys for a session for any Widevine use case. |
| CVE-2024-38426 | MEDIUM | 5.3 | 0.2% | Mar 3, 2025 | While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| CVE-2024-24778 | MEDIUM | 6.5 | 0.6% | Mar 3, 2025 | Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resou... |
| CVE-2024-10925 | MEDIUM | 5.3 | 0.3% | Mar 3, 2025 | A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 1... |
| CVE-2024-8186 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.... |
| CVE-2024-53386 | MEDIUM | 6.1 | 0.2% | Mar 3, 2025 | Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not di... |
| CVE-2024-53382 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but ... |
| CVE-2024-36353 | MEDIUM | 6.5 | 0.1% | Mar 2, 2025 | Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over mem... |
| CVE-2024-55907 | MEDIUM | 5.3 | 0.2% | Mar 2, 2025 | IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain kno... |
| CVE-2024-41778 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, whi... |
| CVE-2024-13833 | HIGH | 7.2 | 0.6% | Mar 1, 2025 | The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, ... |
| CVE-2024-13546 | MEDIUM | 4.3 | 0.3% | Mar 1, 2025 | The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu... |
| CVE-2024-13910 | HIGH | 7.2 | 0.9% | Mar 1, 2025 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file ... |
| CVE-2024-13697 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu... |
| CVE-2024-13611 | HIGH | 7.5 | 0.5% | Mar 1, 2025 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu... |
| CVE-2024-13911 | HIGH | 7.2 | 0.5% | Mar 1, 2025 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Infor... |
| CVE-2024-13806 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl... |
| CVE-2024-12544 | HIGH | 8.8 | 0.7% | Mar 1, 2025 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2024-13373 | HIGH | 8.1 | 0.4% | Mar 1, 2025 | The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up... |
| CVE-2024-12824 | CRITICAL | 9.8 | 2.2% | Mar 1, 2025 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in ... |
| CVE-2024-13901 | MEDIUM | 4.8 | 0.3% | Mar 1, 2025 | The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to... |
| CVE-2024-9217 | MEDIUM | 6.1 | 0.3% | Mar 1, 2025 | The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us... |
| CVE-2024-9212 | MEDIUM | 6.1 | 0.3% | Mar 1, 2025 | The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of... |
| CVE-2024-13750 | MEDIUM | 6.5 | 0.4% | Mar 1, 2025 | The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'or... |
| CVE-2024-13746 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now