2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13385 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-13317 | MEDIUM | 4.3 | 0.2% | Jan 18, 2025 | The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2024-12696 | MEDIUM | 6.4 | 0.4% | Jan 18, 2025 | The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-12385 | MEDIUM | 6.1 | 0.2% | Jan 18, 2025 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-9020 | MEDIUM | 5.4 | 0.3% | Jan 18, 2025 | The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes bef... |
| CVE-2024-13516 | MEDIUM | 6.1 | 0.3% | Jan 18, 2025 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet... |
| CVE-2024-13515 | MEDIUM | 6.1 | 0.4% | Jan 18, 2025 | The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Si... |
| CVE-2024-12071 | MEDIUM | 5.3 | 0.4% | Jan 18, 2025 | The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerab... |
| CVE-2024-11923 | MEDIUM | 5.5 | 0.2% | Jan 18, 2025 | Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Fo... |
| CVE-2024-57252 | MEDIUM | 4.3 | 0.3% | Jan 17, 2025 | OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitr... |
| CVE-2024-57035 | CRITICAL | 9.8 | 0.5% | Jan 17, 2025 | WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php. |
| CVE-2024-57033 | MEDIUM | 6.1 | 0.3% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php. |
| CVE-2024-57372 | MEDIUM | 6.1 | 0.4% | Jan 17, 2025 | Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive inform... |
| CVE-2024-57370 | MEDIUM | 6.1 | 0.4% | Jan 17, 2025 | Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain se... |
| CVE-2024-57369 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | Clickjacking vulnerability in typecho v1.2.1. |
| CVE-2024-57034 | CRITICAL | 9.8 | 0.6% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter. |
| CVE-2024-57032 | CRITICAL | 9.8 | 0.6% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the v... |
| CVE-2024-57031 | CRITICAL | 9.8 | 0.6% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter. |
| CVE-2024-57030 | HIGH | 8.1 | 0.6% | Jan 17, 2025 | Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter. |
| CVE-2024-52870 | HIGH | 7.1 | 0.2% | Jan 17, 2025 | Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unin... |
| CVE-2024-13026 | MEDIUM | 6.1 | 0.1% | Jan 17, 2025 | A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The ... |
| CVE-2024-12757 | HIGH | 8.8 | 0.5% | Jan 17, 2025 | Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker ... |
| CVE-2024-54681 | LOW | 3.5 | 0.3% | Jan 17, 2025 | Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an att... |
| CVE-2024-53683 | MEDIUM | 5.6 | 0.2% | Jan 17, 2025 | A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An... |
| CVE-2024-45832 | MEDIUM | 4.3 | 0.3% | Jan 17, 2025 | Hard-coded credentials were included as part of the application binary. These credentials served as part of the applica... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now