2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26157 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-26156 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-26155 | HIGH | 8.6 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal.... |
| CVE-2024-26154 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-26153 | HIGH | 7.4 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (C... |
| CVE-2024-50967 | MEDIUM | 6.5 | 1.6% | Jan 17, 2025 | The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability.... |
| CVE-2024-13503 | CRITICAL | 9.5 | 0.5% | Jan 17, 2025 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299... |
| CVE-2024-13502 | CRITICAL | 9.3 | 0.6% | Jan 17, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDire... |
| CVE-2024-12703 | HIGH | 8.5 | 0.3% | Jan 17, 2025 | CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an... |
| CVE-2024-12142 | HIGH | 8.8 | 0.3% | Jan 17, 2025 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information di... |
| CVE-2024-10498 | MEDIUM | 6.9 | 0.4% | Jan 17, 2025 | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow a... |
| CVE-2024-10497 | HIGH | 8.8 | 0.5% | Jan 17, 2025 | CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker t... |
| CVE-2024-13378 | MEDIUM | 5.4 | 0.3% | Jan 17, 2025 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter i... |
| CVE-2024-13377 | HIGH | 7.2 | 0.3% | Jan 17, 2025 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versi... |
| CVE-2024-12476 | HIGH | 8.4 | 0.3% | Jan 17, 2025 | CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclos... |
| CVE-2024-12399 | HIGH | 7.1 | 0.2% | Jan 17, 2025 | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t... |
| CVE-2024-12370 | MEDIUM | 5.3 | 0.3% | Jan 17, 2025 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2024-11425 | HIGH | 8.7 | 0.6% | Jan 17, 2025 | CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product whe... |
| CVE-2024-11139 | MEDIUM | 4.6 | 0.2% | Jan 17, 2025 | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow l... |
| CVE-2024-13386 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all ... |
| CVE-2024-13367 | MEDIUM | 6.5 | 0.4% | Jan 17, 2025 | The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_do... |
| CVE-2024-13366 | MEDIUM | 6.1 | 0.3% | Jan 17, 2025 | The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versio... |
| CVE-2024-12637 | MEDIUM | 5.3 | 0.5% | Jan 17, 2025 | The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2024-12598 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ p... |
| CVE-2024-12508 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'g... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now