2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35113 | MEDIUM | 6.5 | 0.3% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through... |
| CVE-2024-35112 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed techn... |
| CVE-2024-35111 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technic... |
| CVE-2024-13562 | HIGH | 7.5 | 0.4% | Jan 25, 2025 | The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Informa... |
| CVE-2024-13450 | MEDIUM | 6.5 | 0.4% | Jan 25, 2025 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
| CVE-2024-13449 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2024-13599 | MEDIUM | 5.4 | 0.3% | Jan 25, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions ... |
| CVE-2024-13586 | MEDIUM | 5.4 | 0.2% | Jan 25, 2025 | The Masy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'justified-gallery' ... |
| CVE-2024-13551 | MEDIUM | 5.4 | 0.3% | Jan 25, 2025 | The ABC Notation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abcjs' shortcode in... |
| CVE-2024-13550 | MEDIUM | 6.5 | 0.6% | Jan 25, 2025 | The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via th... |
| CVE-2024-13548 | MEDIUM | 5.4 | 0.3% | Jan 25, 2025 | The Power Ups for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'magic-bu... |
| CVE-2024-13467 | MEDIUM | 6.1 | 0.3% | Jan 25, 2025 | The WP Contact Form7 Email Spam Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'po... |
| CVE-2024-13458 | MEDIUM | 5.4 | 0.2% | Jan 25, 2025 | The WordPress SEO Friendly Accordion FAQ with AI assisted content generation plugin for WordPress is vulnerable to Store... |
| CVE-2024-13441 | MEDIUM | 5.4 | 0.3% | Jan 25, 2025 | The Bilingual Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bl_otherlang_link_1 param... |
| CVE-2024-13370 | MEDIUM | 6.5 | 0.4% | Jan 25, 2025 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
| CVE-2024-13368 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
| CVE-2024-12885 | MEDIUM | 6.5 | 0.5% | Jan 25, 2025 | The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficien... |
| CVE-2024-12826 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due ... |
| CVE-2024-12817 | MEDIUM | 6.4 | 0.3% | Jan 25, 2025 | The Etsy Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_link' shor... |
| CVE-2024-12816 | MEDIUM | 6.4 | 0.3% | Jan 25, 2025 | The NOTICE BOARD BY TOWKIR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'notice-bo... |
| CVE-2024-12529 | MEDIUM | 6.4 | 0.2% | Jan 25, 2025 | The brodos.net Onlineshop Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Bro... |
| CVE-2024-12512 | MEDIUM | 6.4 | 0.2% | Jan 25, 2025 | The Ask Me Anything (Anonymously) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'as... |
| CVE-2024-12113 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
| CVE-2024-12076 | MEDIUM | 6.1 | 0.3% | Jan 25, 2025 | The Target Video Easy Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2024-11825 | MEDIUM | 6.4 | 0.3% | Jan 25, 2025 | The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘zone’ parameter in all versio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now