2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11299 | HIGH | 7.5 | 0.3% | Apr 22, 2025 | The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2024-13569 | HIGH | 7.1 | 0.5% | Apr 22, 2025 | The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-46899 | HIGH | 7.1 | 0.3% | Apr 22, 2025 | Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentia... |
| CVE-2024-57394 | HIGH | 8.8 | 0.5% | Apr 21, 2025 | The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore ... |
| CVE-2024-13926 | HIGH | 7.5 | 0.4% | Apr 19, 2025 | The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post contain... |
| CVE-2024-42178 | HIGH | 7.5 | 0.2% | Apr 17, 2025 | HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthori... |
| CVE-2024-55211 | HIGH | 8.4 | 0.2% | Apr 17, 2025 | An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie. |
| CVE-2024-55238 | HIGH | 8.8 | 0.5% | Apr 17, 2025 | OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function l... |
| CVE-2024-12530 | HIGH | 7 | 0.2% | Apr 17, 2025 | Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.Thi... |
| CVE-2024-13925 | HIGH | 7.5 | 0.4% | Apr 17, 2025 | The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint ... |
| CVE-2024-53305 | HIGH | 7.3 | 0.5% | Apr 16, 2025 | An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supp... |
| CVE-2024-53303 | HIGH | 8.8 | 0.7% | Apr 16, 2025 | A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 al... |
| CVE-2024-22314 | HIGH | 7.5 | 0.2% | Apr 16, 2025 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that c... |
| CVE-2024-58093 | HIGH | 7.8 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstrea... |
| CVE-2024-52281 | HIGH | 8.9 | 0.5% | Apr 16, 2025 | A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to... |
| CVE-2024-42193 | HIGH | 8.1 | 0.2% | Apr 15, 2025 | HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate valid... |
| CVE-2024-50960 | HIGH | 7.2 | 2.2% | Apr 15, 2025 | A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351... |
| CVE-2024-36842 | HIGH | 7.3 | 0.7% | Apr 15, 2025 | An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220... |
| CVE-2024-56406 | HIGH | 8.4 | 0.5% | Apr 13, 2025 | A heap buffer overflow vulnerability was discovered in Perl. Release branches 5.34, 5.36, 5.38 and 5.40 are affected, ... |
| CVE-2024-13861 | HIGH | 7.8 | 0.2% | Apr 11, 2025 | A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.... |
| CVE-2024-52280 | HIGH | 7.7 | 0.4% | Apr 11, 2025 | A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher which allows users to watch ... |
| CVE-2024-11129 | HIGH | 7.5 | 0.3% | Apr 10, 2025 | An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10... |
| CVE-2024-38865 | HIGH | 8.8 | 0.6% | Apr 10, 2025 | Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0... |
| CVE-2024-13874 | HIGH | 7.1 | 0.2% | Apr 10, 2025 | The Feedify WordPress plugin before 2.4.6 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-55354 | HIGH | 8.8 | 0.1% | Apr 8, 2025 | Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a prot... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now