2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56328 | MEDIUM | 6.1 | 0.3% | Feb 4, 2025 | Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' br... |
| CVE-2024-56197 | MEDIUM | 4.9 | 0.3% | Feb 4, 2025 | Discourse is an open source platform for community discussion. PM titles and metadata can be read by other users when th... |
| CVE-2024-55948 | HIGH | 8.2 | 0.2% | Feb 4, 2025 | Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR re... |
| CVE-2024-45658 | MEDIUM | 5.3 | 0.4% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensiti... |
| CVE-2024-45657 | MEDIUM | 6.7 | 0.1% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform ... |
| CVE-2024-43187 | HIGH | 7.5 | 0.2% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data i... |
| CVE-2024-40700 | MEDIUM | 6.1 | 0.3% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vul... |
| CVE-2024-35138 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery whi... |
| CVE-2024-48019 | MEDIUM | 5.4 | 0.9% | Feb 4, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to Exter... |
| CVE-2024-45659 | MEDIUM | 5.3 | 0.3% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensiti... |
| CVE-2024-9644 | CRITICAL | 9.8 | 0.6% | Feb 4, 2025 | The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the admini... |
| CVE-2024-9643 | CRITICAL | 9.8 | 3.0% | Feb 4, 2025 | The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials i... |
| CVE-2024-23690 | HIGH | 7.2 | 1.2% | Feb 4, 2025 | The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interfac... |
| CVE-2024-11623 | MEDIUM | 4.8 | 0.3% | Feb 4, 2025 | Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application i... |
| CVE-2024-13699 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter... |
| CVE-2024-27137 | MEDIUM | 5.3 | 0.3% | Feb 4, 2025 | In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration... |
| CVE-2024-40891 | HIGH | 8.8 | 19.4% | Feb 4, 2025 | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the le... |
| CVE-2024-40890 | HIGH | 8.8 | 19.3% | Feb 4, 2025 | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL... |
| CVE-2024-13733 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-13529 | MEDIUM | 6.5 | 0.4% | Feb 4, 2025 | The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of ... |
| CVE-2024-13510 | MEDIUM | 6.1 | 0.1% | Feb 4, 2025 | The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.... |
| CVE-2024-13356 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2024-13403 | MEDIUM | 5.4 | 0.4% | Feb 4, 2025 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu... |
| CVE-2024-13514 | MEDIUM | 4.3 | 0.3% | Feb 4, 2025 | The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions u... |
| CVE-2024-12046 | MEDIUM | 4.3 | 0.4% | Feb 4, 2025 | The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now