2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53359 | HIGH | 7.5 | 0.4% | May 20, 2025 | An issue in Zalo v23.09.01 allows attackers to obtain sensitive user information via a crafted GET request. |
| CVE-2024-55063 | HIGH | 8.8 | 0.9% | May 19, 2025 | Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execut... |
| CVE-2024-13613 | HIGH | 7.5 | 0.4% | May 17, 2025 | The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-53827 | HIGH | 7.5 | 0.3% | May 16, 2025 | Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially cra... |
| CVE-2024-9831 | HIGH | 7.2 | 0.5% | May 15, 2025 | The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL stateme... |
| CVE-2024-8700 | HIGH | 7.5 | 0.4% | May 15, 2025 | The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthent... |
| CVE-2024-8699 | HIGH | 7.2 | 0.6% | May 15, 2025 | The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users ... |
| CVE-2024-6719 | HIGH | 8.1 | 0.2% | May 15, 2025 | The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which co... |
| CVE-2024-6486 | HIGH | 7.2 | 2.1% | May 15, 2025 | The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injec... |
| CVE-2024-12812 | HIGH | 7.5 | 0.4% | May 15, 2025 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before... |
| CVE-2024-12735 | HIGH | 7.2 | 0.5% | May 15, 2025 | The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL... |
| CVE-2024-11372 | HIGH | 7.2 | 0.5% | May 15, 2025 | The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL stat... |
| CVE-2024-11269 | HIGH | 7.2 | 0.5% | May 15, 2025 | The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statem... |
| CVE-2024-11267 | HIGH | 8.8 | 0.5% | May 15, 2025 | The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL sta... |
| CVE-2024-0852 | HIGH | 8.8 | 0.6% | May 15, 2025 | The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting i... |
| CVE-2024-0249 | HIGH | 7.1 | 0.3% | May 15, 2025 | The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it... |
| CVE-2024-52880 | HIGH | 7.9 | 0.2% | May 15, 2025 | An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern... |
| CVE-2024-52879 | HIGH | 7.5 | 0.4% | May 15, 2025 | An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern... |
| CVE-2024-52878 | HIGH | 7.5 | 0.4% | May 15, 2025 | An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern... |
| CVE-2024-52877 | HIGH | 7.5 | 0.4% | May 15, 2025 | An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern... |
| CVE-2024-13914 | HIGH | 7.2 | 0.7% | May 15, 2025 | The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an... |
| CVE-2024-45067 | HIGH | 8.2 | 0.1% | May 14, 2025 | Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticat... |
| CVE-2024-55569 | HIGH | 7.5 | 0.4% | May 14, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2024-58101 | HIGH | 8.1 | 0.2% | May 14, 2025 | Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to st... |
| CVE-2024-10864 | HIGH | 7.5 | 0.3% | May 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now