2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49824MEDIUM6.5IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation ...
CVE-2024-49354HIGH7.5IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Call...
CVE-2024-47113CRITICAL9.1IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacke...
CVE-2024-47106HIGH7.5IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information fro...
CVE-2024-51448MEDIUM6.7IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate ...
CVE-2024-49338MEDIUM4.9IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged u...
CVE-2024-13375CRITICAL9.8The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to...
CVE-2024-13184HIGH7.5The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the ...
CVE-2024-13392MEDIUM6.4The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-13519MEDIUM4.4The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-13517MEDIUM4The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored...
CVE-2024-13433MEDIUM6.4The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' short...
CVE-2024-13432MEDIUM6.1The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2024-13393MEDIUM6.4The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2024-13391MEDIUM6.4The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vuln...
CVE-2024-13385MEDIUM6.4The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-13317MEDIUM4.3The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2024-12696MEDIUM6.4The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-12385MEDIUM6.1The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-9020MEDIUM5.4The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes bef...
CVE-2024-13516MEDIUM6.1The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet...
CVE-2024-13515MEDIUM6.1The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Si...
CVE-2024-12071MEDIUM5.3The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerab...
CVE-2024-11923MEDIUM5.5Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Fo...
CVE-2024-57252MEDIUM4.3OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now