2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13770 | CRITICAL | 9.8 | 0.8% | Feb 13, 2025 | The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Inje... |
| CVE-2024-13229 | MEDIUM | 4.3 | 0.4% | Feb 13, 2025 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of dat... |
| CVE-2024-13227 | MEDIUM | 5.4 | 0.4% | Feb 13, 2025 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2024-10763 | CRITICAL | 9.8 | 3.5% | Feb 13, 2025 | The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via th... |
| CVE-2024-13644 | MEDIUM | 5.4 | 0.2% | Feb 13, 2025 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Galle... |
| CVE-2024-8266 | MEDIUM | 6.6 | 0.4% | Feb 13, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attac... |
| CVE-2024-7102 | HIGH | 7.5 | 0.4% | Feb 13, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attack... |
| CVE-2024-51376 | HIGH | 7.5 | 0.9% | Feb 12, 2025 | Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via... |
| CVE-2024-34521 | LOW | 3.5 | 0.6% | Feb 12, 2025 | A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_... |
| CVE-2024-34520 | HIGH | 8.8 | 0.4% | Feb 12, 2025 | An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_... |
| CVE-2024-57605 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the... |
| CVE-2024-57604 | CRITICAL | 9.8 | 0.7% | Feb 12, 2025 | An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component. |
| CVE-2024-57603 | MEDIUM | 6.3 | 0.4% | Feb 12, 2025 | An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting. |
| CVE-2024-57602 | CRITICAL | 9.8 | 0.8% | Feb 12, 2025 | An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php f... |
| CVE-2024-57601 | MEDIUM | 6.1 | 0.5% | Feb 12, 2025 | Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbit... |
| CVE-2024-56940 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) vi... |
| CVE-2024-56939 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body clas... |
| CVE-2024-56938 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the materials-content cl... |
| CVE-2024-51440 | HIGH | 7.8 | 0.2% | Feb 12, 2025 | An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component. |
| CVE-2024-51123 | HIGH | 7.5 | 0.6% | Feb 12, 2025 | An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensi... |
| CVE-2024-51122 | MEDIUM | 6.1 | 0.4% | Feb 12, 2025 | Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 alllows a remote att... |
| CVE-2024-47006 | MEDIUM | 6.7 | 0.2% | Feb 12, 2025 | Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 1... |
| CVE-2024-46923 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a ... |
| CVE-2024-46922 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial ... |
| CVE-2024-42492 | MEDIUM | 6.7 | 0.2% | Feb 12, 2025 | Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family befor... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now