2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57378 | HIGH | 7.3 | 0.3% | Feb 13, 2025 | Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creati... |
| CVE-2024-11347 | HIGH | 7.3 | 0.4% | Feb 13, 2025 | Integer Overflow or Wraparound vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter module... |
| CVE-2024-11346 | HIGH | 7.3 | 0.4% | Feb 13, 2025 | : Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. A... |
| CVE-2024-11345 | HIGH | 7.3 | 0.4% | Feb 13, 2025 | A heap-based memory vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vuln... |
| CVE-2024-11344 | HIGH | 7.3 | 0.4% | Feb 13, 2025 | A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnera... |
| CVE-2024-12013 | HIGH | 7.6 | 0.3% | Feb 13, 2025 | A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12... |
| CVE-2024-12012 | MEDIUM | 5.7 | 0.4% | Feb 13, 2025 | A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway ... |
| CVE-2024-12011 | HIGH | 7.6 | 0.4% | Feb 13, 2025 | A CWE-126 “Buffer Over-read” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The info... |
| CVE-2024-13182 | CRITICAL | 9.8 | 0.6% | Feb 13, 2025 | The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu... |
| CVE-2024-13867 | MEDIUM | 6.1 | 0.3% | Feb 13, 2025 | The Listivo - Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the... |
| CVE-2024-13606 | HIGH | 7.5 | 0.4% | Feb 13, 2025 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information E... |
| CVE-2024-46910 | HIGH | 7.1 | 0.5% | Feb 13, 2025 | An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas version... |
| CVE-2024-3303 | MEDIUM | 5.7 | 0.4% | Feb 13, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior... |
| CVE-2024-13639 | MEDIUM | 4.3 | 0.3% | Feb 13, 2025 | The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a miss... |
| CVE-2024-47266 | LOW | 2.7 | 0.4% | Feb 13, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list function... |
| CVE-2024-47265 | MEDIUM | 6.5 | 0.4% | Feb 13, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount f... |
| CVE-2024-47264 | MEDIUM | 6.5 | 0.5% | Feb 13, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functional... |
| CVE-2024-13346 | CRITICAL | 9.8 | 2.1% | Feb 13, 2025 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode executi... |
| CVE-2024-13345 | CRITICAL | 9.8 | 0.5% | Feb 13, 2025 | The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includi... |
| CVE-2024-13125 | LOW | 3.5 | 0.3% | Feb 13, 2025 | The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-13121 | LOW | 3.5 | 0.3% | Feb 13, 2025 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2024-13120 | MEDIUM | 4.8 | 0.3% | Feb 13, 2025 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2024-13119 | MEDIUM | 4.8 | 0.3% | Feb 13, 2025 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2024-12586 | MEDIUM | 6.1 | 0.3% | Feb 13, 2025 | The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting ... |
| CVE-2024-10083 | MEDIUM | 6.8 | 0.1% | Feb 13, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation whe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now