2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13752 | MEDIUM | 6.5 | 0.5% | Feb 15, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo... |
| CVE-2024-12562 | CRITICAL | 9.8 | 0.9% | Feb 15, 2025 | The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216... |
| CVE-2024-13563 | MEDIUM | 5.4 | 0.3% | Feb 15, 2025 | The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password s... |
| CVE-2024-13525 | MEDIUM | 6.5 | 0.4% | Feb 15, 2025 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in ... |
| CVE-2024-13513 | CRITICAL | 9.8 | 0.7% | Feb 15, 2025 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure ... |
| CVE-2024-13306 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ... |
| CVE-2024-13208 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ... |
| CVE-2024-37375 | — | — | — | Feb 15, 2025 | Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13843. |
| CVE-2024-37374 | — | — | — | Feb 15, 2025 | Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13842. |
| CVE-2024-5462 | HIGH | 7.5 | 0.1% | Feb 15, 2025 | If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP ... |
| CVE-2024-5461 | HIGH | 8 | 0.4% | Feb 15, 2025 | Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch... |
| CVE-2024-4282 | CRITICAL | 9.8 | 0.3% | Feb 15, 2025 | Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22. |
| CVE-2024-10405 | MEDIUM | 5.3 | 0.2% | Feb 15, 2025 | Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, ... |
| CVE-2024-31144 | LOW | 3.8 | 0.2% | Feb 14, 2025 | For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-over... |
| CVE-2024-8893 | HIGH | 7.3 | 0.3% | Feb 14, 2025 | Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximi... |
| CVE-2024-57790 | MEDIUM | 5.4 | 0.2% | Feb 14, 2025 | IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in ... |
| CVE-2024-56463 | MEDIUM | 4.8 | 0.2% | Feb 14, 2025 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrar... |
| CVE-2024-3220 | LOW | 2.3 | 0.5% | Feb 14, 2025 | There is a defect in the CPython standard library module “mimetypes” where on Windows the default list of known file loc... |
| CVE-2024-57778 | HIGH | 8.8 | 0.5% | Feb 14, 2025 | An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the serv... |
| CVE-2024-57725 | MEDIUM | 6.5 | 5.8% | Feb 14, 2025 | An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value wit... |
| CVE-2024-56973 | CRITICAL | 9.8 | 0.8% | Feb 14, 2025 | Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker ... |
| CVE-2024-56477 | MEDIUM | 6.5 | 0.5% | Feb 14, 2025 | IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the syst... |
| CVE-2024-52895 | MEDIUM | 6.5 | 0.4% | Feb 14, 2025 | IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities res... |
| CVE-2024-56180 | CRITICAL | 9.8 | 0.7% | Feb 14, 2025 | CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch wit... |
| CVE-2024-12651 | HIGH | 8.5 | 0.3% | Feb 14, 2025 | Exposed Dangerous Method or Function vulnerability in PTT Inc. HGS Mobile App allows Manipulating User-Controlled Variab... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now