2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38823 | LOW | 2.7 | 0.2% | Jun 13, 2025 | Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport. |
| CVE-2024-38822 | LOW | 2.7 | 0.2% | Jun 13, 2025 | Multiple methods in the salt master skip minion token validation. Therefore a misbehaving minion can impersonate another... |
| CVE-2024-7762 | LOW | 3.7 | 0.3% | May 15, 2025 | The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthen... |
| CVE-2024-6711 | LOW | 3.5 | 0.3% | May 15, 2025 | The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which ... |
| CVE-2024-4091 | LOW | 3.5 | 0.3% | May 15, 2025 | The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-4004 | LOW | 3.5 | 0.3% | May 15, 2025 | The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-4002 | LOW | 3.5 | 0.3% | May 15, 2025 | The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its set... |
| CVE-2024-3996 | LOW | 3.5 | 0.3% | May 15, 2025 | The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow... |
| CVE-2024-12767 | LOW | 3.5 | 0.3% | May 15, 2025 | The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view c... |
| CVE-2024-11140 | LOW | 3.5 | 0.3% | May 15, 2025 | The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of i... |
| CVE-2024-10098 | LOW | 2.7 | 0.3% | May 15, 2025 | The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing ... |
| CVE-2024-12533 | LOW | 3.3 | 0.1% | May 13, 2025 | Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore Technology 4 allows Input Data ... |
| CVE-2024-58253 | LOW | 2.9 | 0.1% | May 2, 2025 | In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to inva... |
| CVE-2024-30146 | LOW | 2.7 | 0.2% | Apr 30, 2025 | Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server... |
| CVE-2024-47784 | LOW | 2.6 | 0.2% | Apr 30, 2025 | Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in th... |
| CVE-2024-12273 | LOW | 3.5 | 0.2% | Apr 29, 2025 | The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could... |
| CVE-2024-12706 | LOW | 2.1 | 0.2% | Apr 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital ... |
| CVE-2024-9771 | LOW | 3.5 | 0.2% | Apr 28, 2025 | The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-57375 | LOW | 2.4 | 0.2% | Apr 25, 2025 | Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to c... |
| CVE-2024-30127 | LOW | 3.2 | 0.1% | Apr 24, 2025 | Missing "no cache" headers in HCL Leap permits sensitive data to be cached. |
| CVE-2024-58251 | LOW | 2.5 | 0.2% | Apr 23, 2025 | In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI t... |
| CVE-2024-11924 | LOW | 3.5 | 0.2% | Apr 17, 2025 | The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape som... |
| CVE-2024-58249 | LOW | 3.7 | 0.4% | Apr 16, 2025 | In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. |
| CVE-2024-58248 | LOW | 3.5 | 0.3% | Apr 16, 2025 | nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate red... |
| CVE-2024-58131 | LOW | 3.7 | 0.2% | Apr 6, 2025 | FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a ma... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now