2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13626 | HIGH | 7.1 | 0.3% | Feb 17, 2025 | The VR-Frases (collect & share quotes) WordPress plugin through 3.0.1 does not sanitise and escape a parameter before ou... |
| CVE-2024-13625 | HIGH | 7.1 | 0.6% | Feb 17, 2025 | The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2024-13608 | MEDIUM | 4.7 | 0.3% | Feb 17, 2025 | The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statemen... |
| CVE-2024-13603 | MEDIUM | 6.1 | 0.4% | Feb 17, 2025 | The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unaut... |
| CVE-2024-44044 | HIGH | 7.1 | 0.2% | Feb 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandexponents Osh... |
| CVE-2024-57971 | CRITICAL | 9.1 | 0.7% | Feb 16, 2025 | DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:... |
| CVE-2024-57970 | MEDIUM | 4 | 0.2% | Feb 16, 2025 | libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c v... |
| CVE-2024-13834 | MEDIUM | 5.4 | 0.2% | Feb 15, 2025 | The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordP... |
| CVE-2024-13500 | MEDIUM | 6.5 | 0.4% | Feb 15, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo... |
| CVE-2024-13488 | HIGH | 7.5 | 1.1% | Feb 15, 2025 | The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' an... |
| CVE-2024-13439 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capab... |
| CVE-2024-10581 | MEDIUM | 4.3 | 0.2% | Feb 15, 2025 | The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2024-13752 | MEDIUM | 6.5 | 0.5% | Feb 15, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo... |
| CVE-2024-12562 | CRITICAL | 9.8 | 0.9% | Feb 15, 2025 | The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216... |
| CVE-2024-13563 | MEDIUM | 5.4 | 0.3% | Feb 15, 2025 | The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password s... |
| CVE-2024-13525 | MEDIUM | 6.5 | 0.4% | Feb 15, 2025 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in ... |
| CVE-2024-13513 | CRITICAL | 9.8 | 0.7% | Feb 15, 2025 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure ... |
| CVE-2024-13306 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ... |
| CVE-2024-13208 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ... |
| CVE-2024-37375 | — | — | — | Feb 15, 2025 | Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13843. |
| CVE-2024-37374 | — | — | — | Feb 15, 2025 | Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13842. |
| CVE-2024-5462 | HIGH | 7.5 | 0.1% | Feb 15, 2025 | If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP ... |
| CVE-2024-5461 | HIGH | 8 | 0.4% | Feb 15, 2025 | Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch... |
| CVE-2024-4282 | CRITICAL | 9.8 | 0.3% | Feb 15, 2025 | Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22. |
| CVE-2024-10405 | MEDIUM | 5.3 | 0.2% | Feb 15, 2025 | Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now