2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13494 | MEDIUM | 4.3 | 0.2% | Feb 25, 2025 | The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-10545 | LOW | 3.5 | 0.3% | Feb 25, 2025 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.9 does not sanitise and escape some of its Image... |
| CVE-2024-57685 | MEDIUM | 5.3 | 0.4% | Feb 24, 2025 | An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file. |
| CVE-2024-56525 | CRITICAL | 9.8 | 0.4% | Feb 24, 2025 | In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journ... |
| CVE-2024-53544 | CRITICAL | 9.8 | 0.4% | Feb 24, 2025 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability... |
| CVE-2024-53543 | MEDIUM | 5.4 | 0.2% | Feb 24, 2025 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability... |
| CVE-2024-53542 | MEDIUM | 6.5 | 0.2% | Feb 24, 2025 | Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Tim... |
| CVE-2024-57608 | MEDIUM | 6.5 | 0.4% | Feb 24, 2025 | An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component. |
| CVE-2024-57026 | MEDIUM | 6.1 | 0.4% | Feb 24, 2025 | TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that al... |
| CVE-2024-54820 | CRITICAL | 9.8 | 1.1% | Feb 24, 2025 | XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login ... |
| CVE-2024-56897 | CRITICAL | 9.8 | 0.7% | Feb 24, 2025 | Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API ... |
| CVE-2024-12918 | HIGH | 8.8 | 0.4% | Feb 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Hea... |
| CVE-2024-12917 | HIGH | 8.3 | 0.4% | Feb 24, 2025 | Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorre... |
| CVE-2024-12916 | HIGH | 8.8 | 0.4% | Feb 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Lif... |
| CVE-2024-5174 | MEDIUM | 5.3 | 0.3% | Feb 24, 2025 | A flaw in Gliffy results in broken authentication through the reset functionality of the application. |
| CVE-2024-13822 | MEDIUM | 6.1 | 0.3% | Feb 24, 2025 | The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter... |
| CVE-2024-13605 | MEDIUM | 4.8 | 0.3% | Feb 24, 2025 | The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-12308 | MEDIUM | 5.4 | 0.3% | Feb 24, 2025 | The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2024-55898 | HIGH | 8.5 | 0.4% | Feb 24, 2025 | IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated pri... |
| CVE-2024-13728 | MEDIUM | 6.1 | 0.3% | Feb 23, 2025 | The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the r... |
| CVE-2024-52939 | HIGH | 7.8 | 0.2% | Feb 22, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ... |
| CVE-2024-47896 | LOW | 3.3 | 0.1% | Feb 22, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou... |
| CVE-2024-46975 | HIGH | 7.9 | 0.1% | Feb 22, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data in... |
| CVE-2024-12577 | HIGH | 7.3 | 0.2% | Feb 22, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou... |
| CVE-2024-13869 | HIGH | 7.2 | 2.1% | Feb 22, 2025 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now