2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13639 | MEDIUM | 4.3 | 0.3% | Feb 13, 2025 | The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a miss... |
| CVE-2024-47266 | LOW | 2.7 | 0.4% | Feb 13, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list function... |
| CVE-2024-47265 | MEDIUM | 6.5 | 0.4% | Feb 13, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount f... |
| CVE-2024-47264 | MEDIUM | 6.5 | 0.5% | Feb 13, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functional... |
| CVE-2024-13346 | CRITICAL | 9.8 | 2.1% | Feb 13, 2025 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode executi... |
| CVE-2024-13345 | CRITICAL | 9.8 | 0.5% | Feb 13, 2025 | The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includi... |
| CVE-2024-13125 | LOW | 3.5 | 0.3% | Feb 13, 2025 | The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-13121 | LOW | 3.5 | 0.3% | Feb 13, 2025 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2024-13120 | MEDIUM | 4.8 | 0.3% | Feb 13, 2025 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2024-13119 | MEDIUM | 4.8 | 0.3% | Feb 13, 2025 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2024-12586 | MEDIUM | 6.1 | 0.3% | Feb 13, 2025 | The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting ... |
| CVE-2024-10083 | MEDIUM | 6.8 | 0.1% | Feb 13, 2025 | CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation whe... |
| CVE-2024-13770 | CRITICAL | 9.8 | 0.8% | Feb 13, 2025 | The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Inje... |
| CVE-2024-13229 | MEDIUM | 4.3 | 0.4% | Feb 13, 2025 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of dat... |
| CVE-2024-13227 | MEDIUM | 5.4 | 0.4% | Feb 13, 2025 | The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2024-10763 | CRITICAL | 9.8 | 3.5% | Feb 13, 2025 | The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via th... |
| CVE-2024-13644 | MEDIUM | 5.4 | 0.2% | Feb 13, 2025 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Galle... |
| CVE-2024-8266 | MEDIUM | 6.6 | 0.4% | Feb 13, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attac... |
| CVE-2024-7102 | HIGH | 7.5 | 0.4% | Feb 13, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attack... |
| CVE-2024-51376 | HIGH | 7.5 | 0.9% | Feb 12, 2025 | Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via... |
| CVE-2024-34521 | LOW | 3.5 | 0.6% | Feb 12, 2025 | A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_... |
| CVE-2024-34520 | HIGH | 8.8 | 0.4% | Feb 12, 2025 | An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_... |
| CVE-2024-57605 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the... |
| CVE-2024-57604 | CRITICAL | 9.8 | 0.7% | Feb 12, 2025 | An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component. |
| CVE-2024-57603 | MEDIUM | 6.3 | 0.4% | Feb 12, 2025 | An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now