2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12600 | HIGH | 7.2 | 0.7% | Jan 25, 2025 | The Custom Product Tabs Lite for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions ... |
| CVE-2024-10552 | MEDIUM | 6.4 | 0.3% | Jan 25, 2025 | The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘api_key’ and 'api_sec... |
| CVE-2024-13721 | MEDIUM | 6.4 | 0.3% | Jan 25, 2025 | The Plethora Plugins Tabs + Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the anchor ... |
| CVE-2024-13709 | MEDIUM | 4.3 | 0.2% | Jan 25, 2025 | The Linear plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1.... |
| CVE-2024-50698 | CRITICAL | 9.8 | 0.6% | Jan 24, 2025 | SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of... |
| CVE-2024-50697 | HIGH | 8.1 | 0.4% | Jan 24, 2025 | In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TL... |
| CVE-2024-50695 | CRITICAL | 9.8 | 0.6% | Jan 24, 2025 | SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT mess... |
| CVE-2024-50694 | CRITICAL | 9.8 | 0.6% | Jan 24, 2025 | In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the under... |
| CVE-2024-50692 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send ... |
| CVE-2024-50690 | MEDIUM | 6.5 | 0.2% | Jan 24, 2025 | SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmw... |
| CVE-2024-57277 | MEDIUM | 5.7 | 0.5% | Jan 24, 2025 | InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload. |
| CVE-2024-57095 | MEDIUM | 6.8 | 0.6% | Jan 24, 2025 | SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload. |
| CVE-2024-57041 | MEDIUM | 4.6 | 26.1% | Jan 24, 2025 | A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code ... |
| CVE-2024-52807 | HIGH | 8.6 | 0.5% | Jan 24, 2025 | The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT ... |
| CVE-2024-56404 | CRITICAL | 9.9 | 0.6% | Jan 24, 2025 | In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privile... |
| CVE-2024-35122 | LOW | 2.8 | 0.2% | Jan 24, 2025 | IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority r... |
| CVE-2024-45077 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated ... |
| CVE-2024-41757 | MEDIUM | 5.9 | 0.3% | Jan 24, 2025 | IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failur... |
| CVE-2024-40706 | MEDIUM | 4.3 | 0.4% | Jan 24, 2025 | IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid ... |
| CVE-2024-40693 | HIGH | 8 | 0.4% | Jan 24, 2025 | IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the content of the fil... |
| CVE-2024-25034 | HIGH | 8.8 | 0.4% | Jan 24, 2025 | IBM Planning Analytics 2.0 and 2.1 could be vulnerable to malicious file upload by not validating the type of file in th... |
| CVE-2024-13698 | MEDIUM | 6.5 | 0.3% | Jan 24, 2025 | The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due t... |
| CVE-2024-9499 | HIGH | 8.6 | 0.2% | Jan 24, 2025 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Win 98SE Dev Kit installer can lea... |
| CVE-2024-9498 | HIGH | 8.6 | 0.2% | Jan 24, 2025 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress SDK installer can lead to p... |
| CVE-2024-9497 | HIGH | 8.6 | 0.2% | Jan 24, 2025 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now