2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12590 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The WP Youtube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all v... |
| CVE-2024-12559 | MEDIUM | 5.3 | 0.4% | Jan 7, 2025 | The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2024-12557 | MEDIUM | 6.1 | 0.2% | Jan 7, 2025 | The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2024-12541 | MEDIUM | 5.4 | 0.2% | Jan 7, 2025 | The Chative Live chat and Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2024-12538 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all... |
| CVE-2024-12528 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-12419 | MEDIUM | 6.5 | 0.4% | Jan 7, 2025 | The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to arbitrar... |
| CVE-2024-12098 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | The ARS Affiliate Page Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'utm_keyword'... |
| CVE-2024-11934 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-11899 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Slider Pro Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sliderpro' short... |
| CVE-2024-11777 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_for... |
| CVE-2024-11437 | MEDIUM | 4.9 | 0.5% | Jan 7, 2025 | The Timeline Designer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, a... |
| CVE-2024-54764 | MEDIUM | 6.5 | 1.0% | Jan 6, 2025 | An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensit... |
| CVE-2024-54763 | MEDIUM | 6.5 | 0.7% | Jan 6, 2025 | An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensiti... |
| CVE-2024-53936 | MEDIUM | 6.3 | 0.2% | Jan 6, 2025 | The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any applicati... |
| CVE-2024-53935 | MEDIUM | 6.5 | 0.2% | Jan 6, 2025 | The com.callos14.callscreen.colorphone (aka iCall OS17 - Color Phone Flash) application through 4.3 for Android enables ... |
| CVE-2024-53933 | MEDIUM | 6.3 | 0.2% | Jan 6, 2025 | The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Andr... |
| CVE-2024-51741 | MEDIUM | 4.4 | 0.3% | Jan 6, 2025 | Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat... |
| CVE-2024-55075 | MEDIUM | 5.3 | 0.5% | Jan 6, 2025 | Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not sh... |
| CVE-2024-55408 | MEDIUM | 5.3 | 0.2% | Jan 6, 2025 | An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality uti... |
| CVE-2024-46209 | MEDIUM | 5.4 | 0.4% | Jan 6, 2025 | A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attacke... |
| CVE-2024-35498 | MEDIUM | 6.1 | 0.4% | Jan 6, 2025 | A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via... |
| CVE-2024-55626 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-46073 | MEDIUM | 6.1 | 0.4% | Jan 6, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is... |
| CVE-2024-56769 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: dib3000mb: fix uninit-value i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now