2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13797 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode ex... |
| CVE-2024-12860 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via accoun... |
| CVE-2024-13556 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Ob... |
| CVE-2024-13725 | CRITICAL | 9.8 | 1.3% | Feb 18, 2025 | The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc... |
| CVE-2024-57971 | CRITICAL | 9.1 | 0.7% | Feb 16, 2025 | DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:... |
| CVE-2024-12562 | CRITICAL | 9.8 | 0.9% | Feb 15, 2025 | The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216... |
| CVE-2024-13513 | CRITICAL | 9.8 | 0.7% | Feb 15, 2025 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure ... |
| CVE-2024-4282 | CRITICAL | 9.8 | 0.3% | Feb 15, 2025 | Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22. |
| CVE-2024-56973 | CRITICAL | 9.8 | 0.8% | Feb 14, 2025 | Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker ... |
| CVE-2024-56180 | CRITICAL | 9.8 | 0.7% | Feb 14, 2025 | CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch wit... |
| CVE-2024-13152 | CRITICAL | 10 | 0.5% | Feb 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy... |
| CVE-2024-52577 | CRITICAL | 9 | 2.4% | Feb 14, 2025 | In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Igni... |
| CVE-2024-13182 | CRITICAL | 9.8 | 0.6% | Feb 13, 2025 | The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inclu... |
| CVE-2024-13346 | CRITICAL | 9.8 | 2.1% | Feb 13, 2025 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode executi... |
| CVE-2024-13345 | CRITICAL | 9.8 | 0.5% | Feb 13, 2025 | The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includi... |
| CVE-2024-13770 | CRITICAL | 9.8 | 0.8% | Feb 13, 2025 | The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Inje... |
| CVE-2024-10763 | CRITICAL | 9.8 | 3.5% | Feb 13, 2025 | The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via th... |
| CVE-2024-57604 | CRITICAL | 9.8 | 0.7% | Feb 12, 2025 | An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component. |
| CVE-2024-57602 | CRITICAL | 9.8 | 0.8% | Feb 12, 2025 | An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php f... |
| CVE-2024-13477 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | The LTL Freight Quotes – Unishippers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' param... |
| CVE-2024-13365 | CRITICAL | 9.8 | 1.5% | Feb 12, 2025 | The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to arbitrary file uploads due to the plugin ... |
| CVE-2024-12213 | CRITICAL | 9.8 | 0.6% | Feb 12, 2025 | The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is du... |
| CVE-2024-13421 | CRITICAL | 9.8 | 0.7% | Feb 12, 2025 | The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi... |
| CVE-2024-27781 | CRITICAL | 9 | 22.0% | Feb 11, 2025 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS... |
| CVE-2024-12366 | CRITICAL | 9.8 | 1.2% | Feb 11, 2025 | PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now