2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50687 | CRITICAL | 9.1 | 0.4% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50686 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50685 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) v... |
| CVE-2024-50684 | MEDIUM | 6.5 | 0.3% | Feb 26, 2025 | SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient ... |
| CVE-2024-53427 | HIGH | 8.1 | 0.4% | Feb 26, 2025 | decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which ha... |
| CVE-2024-46226 | MEDIUM | 4.8 | 0.2% | Feb 26, 2025 | A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary Jav... |
| CVE-2024-52925 | MEDIUM | 6.8 | 0.3% | Feb 26, 2025 | In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unl... |
| CVE-2024-6810 | MEDIUM | 4.4 | 0.5% | Feb 26, 2025 | The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin... |
| CVE-2024-47053 | HIGH | 7.7 | 0.7% | Feb 26, 2025 | This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw c... |
| CVE-2024-47051 | CRITICAL | 9.9 | 1.7% | Feb 26, 2025 | This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabili... |
| CVE-2024-39441 | HIGH | 8.4 | 0.1% | Feb 26, 2025 | In wifi display, there is a possible missing permission check. This could lead to local escalation of privilege with no ... |
| CVE-2024-13803 | MEDIUM | 5.4 | 0.4% | Feb 26, 2025 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-13678 | MEDIUM | 6.1 | 0.4% | Feb 26, 2025 | The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2024-13669 | MEDIUM | 6.1 | 0.4% | Feb 26, 2025 | The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-13634 | MEDIUM | 6.1 | 0.6% | Feb 26, 2025 | The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-13633 | HIGH | 7.1 | 0.4% | Feb 26, 2025 | The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-13632 | HIGH | 7.1 | 0.4% | Feb 26, 2025 | The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2024-13631 | HIGH | 7.1 | 0.3% | Feb 26, 2025 | The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in th... |
| CVE-2024-13630 | MEDIUM | 6.1 | 0.6% | Feb 26, 2025 | The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13629 | MEDIUM | 6.1 | 0.4% | Feb 26, 2025 | The pushBIZ WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page... |
| CVE-2024-13628 | MEDIUM | 6.1 | 0.6% | Feb 26, 2025 | The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2024-13624 | HIGH | 7.1 | 0.7% | Feb 26, 2025 | The WPMovieLibrary WordPress plugin through 2.1.4.8 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-13571 | HIGH | 7.1 | 0.3% | Feb 26, 2025 | The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2024-13560 | MEDIUM | 4.3 | 0.3% | Feb 26, 2025 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi... |
| CVE-2024-13113 | MEDIUM | 5.9 | 0.3% | Feb 26, 2025 | The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when output... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now