2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12436MEDIUM4.3The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attacker...
CVE-2024-12321HIGH7.1The WC Affiliate WordPress plugin through 2.3.9 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-12280MEDIUM4.3The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which coul...
CVE-2024-28771MEDIUM6.5IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr...
CVE-2024-28770MEDIUM6.5IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr...
CVE-2024-28766HIGH7.5IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive inf...
CVE-2024-31906MEDIUM6.2IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the s...
CVE-2024-13505MEDIUM4.8The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8...
CVE-2024-12334MEDIUM6.1The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Sc...
CVE-2024-11936HIGH8.8The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalatio...
CVE-2024-11641HIGH8.8The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio...
CVE-2024-46881HIGH7.1Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control confi...
CVE-2024-11090HIGH7.5The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver...
CVE-2024-10705HIGH8.1The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio...
CVE-2024-10636MEDIUM6.1The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via...
CVE-2024-10633HIGH7.3The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in a...
CVE-2024-10628HIGH7.5The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ paramet...
CVE-2024-10574HIGH7.2The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data ...
CVE-2024-35150MEDIUM5.3IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is wr...
CVE-2024-35148HIGH8.8IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attac...
CVE-2024-35145MEDIUM6.1IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2024-35144MEDIUM5.3IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid...
CVE-2024-39750HIGH8.8IBM Analytics Content Hub 2.0 is vulnerable to a buffer overflow due to improper return length checking. A remote authen...
CVE-2024-35134MEDIUM5.3IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical er...
CVE-2024-35114MEDIUM5.3IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now