2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49337 | MEDIUM | 5.4 | 0.2% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation... |
| CVE-2024-6432 | MEDIUM | 5.4 | 0.3% | Feb 20, 2025 | The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘conte... |
| CVE-2024-13855 | MEDIUM | 4.3 | 0.3% | Feb 20, 2025 | The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up... |
| CVE-2024-13849 | MEDIUM | 4.8 | 0.3% | Feb 20, 2025 | The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu... |
| CVE-2024-13802 | MEDIUM | 5.4 | 0.3% | Feb 20, 2025 | The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_e... |
| CVE-2024-13792 | CRITICAL | 9.8 | 0.5% | Feb 20, 2025 | The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode executi... |
| CVE-2024-13789 | CRITICAL | 9.8 | 0.8% | Feb 20, 2025 | The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via de... |
| CVE-2024-13753 | HIGH | 8.8 | 0.2% | Feb 20, 2025 | The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2024-13748 | MEDIUM | 4.8 | 0.2% | Feb 20, 2025 | The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title paramet... |
| CVE-2024-13520 | MEDIUM | 5.3 | 0.3% | Feb 20, 2025 | The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized m... |
| CVE-2024-13476 | HIGH | 7.5 | 0.4% | Feb 20, 2025 | The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to SQL Injection via the 'engtz_wd_save_... |
| CVE-2024-13888 | MEDIUM | 6.1 | 0.7% | Feb 20, 2025 | The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This i... |
| CVE-2024-13155 | MEDIUM | 5.4 | 0.3% | Feb 20, 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-13445 | MEDIUM | 5.4 | 0.3% | Feb 20, 2025 | The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-49782 | HIGH | 8.2 | 0.3% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 could allow a remote attacker to spoof mail server identity when using SSL/TLS... |
| CVE-2024-49780 | MEDIUM | 6.5 | 0.5% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system.... |
| CVE-2024-49355 | MEDIUM | 6.5 | 0.3% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enab... |
| CVE-2024-43196 | MEDIUM | 4.3 | 0.2% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 application could allow an authenticated user to manipulate data in the Question... |
| CVE-2024-6697 | MEDIUM | 6.5 | 0.3% | Feb 20, 2025 | The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functional... |
| CVE-2024-6696 | MEDIUM | 4.9 | 0.3% | Feb 20, 2025 | The product implements access controls via a policy or other feature with the intention to disable or restrict accesses ... |
| CVE-2024-37363 | MEDIUM | 6.5 | 0.3% | Feb 20, 2025 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (C... |
| CVE-2024-37362 | MEDIUM | 6.3 | 0.3% | Feb 20, 2025 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauth... |
| CVE-2024-37361 | CRITICAL | 9.9 | 0.5% | Feb 20, 2025 | The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-5... |
| CVE-2024-12284 | HIGH | 8.8 | 11.9% | Feb 20, 2025 | Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. |
| CVE-2024-5706 | HIGH | 8.8 | 0.7% | Feb 19, 2025 | The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input befor... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now