2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12171 | HIGH | 8.8 | 0.5% | Feb 1, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due t... |
| CVE-2024-11780 | MEDIUM | 5.4 | 0.2% | Feb 1, 2025 | The Site Search 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ss360-resultbloc... |
| CVE-2024-57587 | CRITICAL | 9.1 | 0.5% | Jan 31, 2025 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated ... |
| CVE-2024-57435 | MEDIUM | 6.5 | 0.4% | Jan 31, 2025 | In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a nul... |
| CVE-2024-57434 | HIGH | 8.8 | 0.4% | Jan 31, 2025 | macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test... |
| CVE-2024-57433 | HIGH | 7.5 | 0.4% | Jan 31, 2025 | macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, the... |
| CVE-2024-55062 | CRITICAL | 9.8 | 1.0% | Jan 31, 2025 | Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers ... |
| CVE-2024-53357 | HIGH | 7.5 | 0.5% | Jan 31, 2025 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated at... |
| CVE-2024-53356 | CRITICAL | 9.8 | 0.6% | Jan 31, 2025 | Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JW... |
| CVE-2024-53355 | HIGH | 8.8 | 0.5% | Jan 31, 2025 | Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated ... |
| CVE-2024-53354 | MEDIUM | 6.5 | 0.5% | Jan 31, 2025 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated at... |
| CVE-2024-57432 | HIGH | 7.5 | 0.5% | Jan 31, 2025 | macrozheng mall-tiny 1.0.1 suffers from Insecure Permissions. The application's JWT signing keys are hardcoded and do no... |
| CVE-2024-53584 | CRITICAL | 9.8 | 4.4% | Jan 31, 2025 | OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter. |
| CVE-2024-49349 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored ... |
| CVE-2024-49339 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored ... |
| CVE-2024-47857 | CRITICAL | 9.8 | 0.4% | Jan 31, 2025 | SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures w... |
| CVE-2024-42671 | MEDIUM | 6.1 | 0.3% | Jan 31, 2025 | A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirec... |
| CVE-2024-53582 | HIGH | 7.5 | 3.1% | Jan 31, 2025 | An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to exec... |
| CVE-2024-53537 | CRITICAL | 9.1 | 2.2% | Jan 31, 2025 | An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager... |
| CVE-2024-53320 | CRITICAL | 9.8 | 0.4% | Jan 31, 2025 | Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveC... |
| CVE-2024-53319 | HIGH | 7.5 | 0.4% | Jan 31, 2025 | A heap buffer overflow in the XML Text Escaping component of Qualisys C++ SDK commit a32a21a allows attackers to cause D... |
| CVE-2024-49807 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored... |
| CVE-2024-47116 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-... |
| CVE-2024-47103 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-... |
| CVE-2024-45089 | MEDIUM | 4.3 | 0.3% | Jan 31, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now