2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7103 | MEDIUM | 5.4 | 0.2% | May 22, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the sub-organization login flow of WSO2 Identity Server 7... |
| CVE-2024-13958 | MEDIUM | 4.8 | 0.2% | May 22, 2025 | Stored Cross Site Scripting vulnerabilities exist in ASPECT if administrator creden-tials become compromisedThis issue a... |
| CVE-2024-13954 | MEDIUM | 6.5 | 0.2% | May 22, 2025 | Serialized configuration information may be disclosed during device commissioning while using ASPECT's configuration too... |
| CVE-2024-13953 | MEDIUM | 6.9 | 0.3% | May 22, 2025 | Sensitive device logger information in ASPECT may be exposed if administrator credentials become compromisedThis issue a... |
| CVE-2024-13950 | MEDIUM | 6.9 | 0.3% | May 22, 2025 | Log injection vulnerabilities in ASPECT provide attacker access to inject malicious browser scripts if administrator cre... |
| CVE-2024-13949 | MEDIUM | 6.9 | 0.3% | May 22, 2025 | Large content vulnerabilities are present in ASPECT exposing a device to disk overutilization on a system if administrat... |
| CVE-2024-13930 | MEDIUM | 5.9 | 0.3% | May 22, 2025 | An Unchecked Loop Condition in ASPECT provides an attacker the ability to maliciously consume system resources if sessio... |
| CVE-2024-54188 | MEDIUM | 5.3 | 5.8% | May 22, 2025 | Infoblox NETMRI before 7.6.1 has a vulnerability allowing remote authenticated users to read arbitrary files with root a... |
| CVE-2024-12093 | MEDIUM | 6.8 | 0.4% | May 22, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and ... |
| CVE-2024-9544 | MEDIUM | 6.4 | 0.2% | May 22, 2025 | The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,... |
| CVE-2024-57529 | MEDIUM | 6.1 | 0.4% | May 21, 2025 | Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary c... |
| CVE-2024-56428 | MEDIUM | 5.5 | 0.1% | May 21, 2025 | The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the C... |
| CVE-2024-23337 | MEDIUM | 6.5 | 0.4% | May 21, 2025 | jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning va... |
| CVE-2024-42922 | MEDIUM | 6.5 | 0.9% | May 21, 2025 | AAPanel v7.0.7 was discovered to contain an OS command injection vulnerability. |
| CVE-2024-12561 | MEDIUM | 6.1 | 0.3% | May 21, 2025 | The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versi... |
| CVE-2024-45641 | MEDIUM | 6.5 | 0.2% | May 20, 2025 | IBM Security ReaQta EDR 3.12 could allow an attacker to perform unauthorized actions due to improper SSL certificate val... |
| CVE-2024-5878 | MEDIUM | 6.4 | 0.3% | May 20, 2025 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox Jav... |
| CVE-2024-33939 | MEDIUM | 5.3 | 0.8% | May 19, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in masteriyo Masteriyo - LMS learning-management-... |
| CVE-2024-51106 | MEDIUM | 4.6 | 0.2% | May 19, 2025 | A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation... |
| CVE-2024-47893 | MEDIUM | 6.5 | 0.2% | May 17, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or w... |
| CVE-2024-40120 | MEDIUM | 6.5 | 0.2% | May 16, 2025 | seaweedfs v3.68 was discovered to contain a SQL injection vulnerability via the component /abstract_sql/abstract_sql_sto... |
| CVE-2024-8201 | MEDIUM | 5.4 | 0.1% | May 16, 2025 | Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent component).This issue affects Hi... |
| CVE-2024-51475 | MEDIUM | 6.1 | 0.2% | May 16, 2025 | IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to HTML injection. A remote attacker could inject maliciou... |
| CVE-2024-9882 | MEDIUM | 4.8 | 0.2% | May 15, 2025 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses WordPress plugin before 1.9.4 does ... |
| CVE-2024-9879 | MEDIUM | 5.4 | 0.3% | May 15, 2025 | The Melapress File Monitor WordPress plugin before 2.1.1 does not sanitize and escape a parameter before using it in a S... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now