2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49824 | MEDIUM | 6.5 | 0.3% | Jan 18, 2025 | IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation ... |
| CVE-2024-49354 | HIGH | 7.5 | 0.3% | Jan 18, 2025 | IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Call... |
| CVE-2024-47113 | CRITICAL | 9.1 | 0.6% | Jan 18, 2025 | IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacke... |
| CVE-2024-47106 | HIGH | 7.5 | 0.4% | Jan 18, 2025 | IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information fro... |
| CVE-2024-51448 | MEDIUM | 6.7 | 0.1% | Jan 18, 2025 | IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate ... |
| CVE-2024-49338 | MEDIUM | 4.9 | 0.4% | Jan 18, 2025 | IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged u... |
| CVE-2024-13375 | CRITICAL | 9.8 | 1.4% | Jan 18, 2025 | The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to... |
| CVE-2024-13184 | HIGH | 7.5 | 0.5% | Jan 18, 2025 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the ... |
| CVE-2024-13392 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-13519 | MEDIUM | 4.4 | 0.3% | Jan 18, 2025 | The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-13517 | MEDIUM | 4 | 0.2% | Jan 18, 2025 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored... |
| CVE-2024-13433 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' short... |
| CVE-2024-13432 | MEDIUM | 6.1 | 0.2% | Jan 18, 2025 | The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2024-13393 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2024-13391 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vuln... |
| CVE-2024-13385 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-13317 | MEDIUM | 4.3 | 0.2% | Jan 18, 2025 | The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2024-12696 | MEDIUM | 6.4 | 0.4% | Jan 18, 2025 | The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-12385 | MEDIUM | 6.1 | 0.2% | Jan 18, 2025 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-9020 | MEDIUM | 5.4 | 0.3% | Jan 18, 2025 | The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes bef... |
| CVE-2024-13516 | MEDIUM | 6.1 | 0.3% | Jan 18, 2025 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet... |
| CVE-2024-13515 | MEDIUM | 6.1 | 0.4% | Jan 18, 2025 | The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Si... |
| CVE-2024-12071 | MEDIUM | 5.3 | 0.4% | Jan 18, 2025 | The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerab... |
| CVE-2024-11923 | MEDIUM | 5.5 | 0.2% | Jan 18, 2025 | Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Fo... |
| CVE-2024-57252 | MEDIUM | 4.3 | 0.3% | Jan 17, 2025 | OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now