2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9496 | HIGH | 8.6 | 0.2% | Jan 24, 2025 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Dev Kit installer can lead ... |
| CVE-2024-9495 | HIGH | 8.6 | 0.2% | Jan 24, 2025 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the CP210x VCP Windows installer can lead t... |
| CVE-2024-9494 | HIGH | 8.6 | 0.2% | Jan 24, 2025 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the CP210 VCP Win 2k installer can lead ... |
| CVE-2024-9493 | HIGH | 8.6 | 0.2% | Jan 24, 2025 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the ToolStick installer can lead to privileg... |
| CVE-2024-9492 | HIGH | 8.6 | 0.2% | Jan 24, 2025 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in Flash Programming Utility installer can lead to ... |
| CVE-2024-9491 | HIGH | 8.6 | 0.2% | Jan 24, 2025 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in Configuration Wizard 2 installer can lead to pri... |
| CVE-2024-9490 | HIGH | 8.6 | 0.2% | Jan 24, 2025 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in Silicon Labs (8-bit) IDE installer can lead to p... |
| CVE-2024-57184 | MEDIUM | 5.5 | 0.3% | Jan 24, 2025 | An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_p... |
| CVE-2024-41739 | HIGH | 8.8 | 0.4% | Jan 24, 2025 | IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized action... |
| CVE-2024-11913 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all... |
| CVE-2024-10324 | MEDIUM | 4.3 | 0.3% | Jan 24, 2025 | The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t... |
| CVE-2024-13594 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofi... |
| CVE-2024-13572 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | The Precious Metals Charts and Widgets for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-13542 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Store... |
| CVE-2024-13409 | HIGH | 8.8 | 0.8% | Jan 24, 2025 | The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is v... |
| CVE-2024-13408 | HIGH | 8.8 | 0.6% | Jan 24, 2025 | The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is v... |
| CVE-2024-13354 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne... |
| CVE-2024-13335 | MEDIUM | 4.3 | 0.2% | Jan 24, 2025 | The Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templates plugin for WordPress is vulnerable to unau... |
| CVE-2024-13583 | MEDIUM | 5.4 | 0.3% | Jan 24, 2025 | The Simple Gallery with Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c2tw_... |
| CVE-2024-12494 | MEDIUM | 5.4 | 0.3% | Jan 24, 2025 | The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_ma... |
| CVE-2024-13545 | CRITICAL | 9.8 | 1.3% | Jan 24, 2025 | The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1... |
| CVE-2024-13683 | MEDIUM | 4.3 | 0.2% | Jan 24, 2025 | The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2024-13680 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL... |
| CVE-2024-13659 | MEDIUM | 5.4 | 0.3% | Jan 24, 2025 | The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortco... |
| CVE-2024-11931 | MEDIUM | 5.3 | 0.3% | Jan 24, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now