2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12218 | MEDIUM | 6.1 | 0.2% | Jan 9, 2025 | The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in a... |
| CVE-2024-12206 | MEDIUM | 4.3 | 0.2% | Jan 9, 2025 | The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers... |
| CVE-2024-12122 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions ... |
| CVE-2024-12067 | MEDIUM | 6.5 | 0.5% | Jan 9, 2025 | The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injecti... |
| CVE-2024-11929 | MEDIUM | 6.4 | 0.3% | Jan 9, 2025 | The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp... |
| CVE-2024-11907 | MEDIUM | 6.4 | 0.4% | Jan 9, 2025 | The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_ifram... |
| CVE-2024-11815 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via... |
| CVE-2024-11686 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts... |
| CVE-2024-11642 | CRITICAL | 9.8 | 1.0% | Jan 9, 2025 | The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginatio... |
| CVE-2024-11328 | MEDIUM | 6.1 | 0.5% | Jan 9, 2025 | The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use ... |
| CVE-2024-13153 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widg... |
| CVE-2024-12802 | CRITICAL | 9.1 | 0.5% | Jan 9, 2025 | SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal ... |
| CVE-2024-43663 | CRITICAL | 9.8 | 1.0% | Jan 9, 2025 | There are many buffer overflow vulnerabilities present in several CGI binaries of the charging station.This issue affect... |
| CVE-2024-43662 | MEDIUM | 5.3 | 0.6% | Jan 9, 2025 | The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectiv... |
| CVE-2024-43661 | CRITICAL | 9.8 | 0.5% | Jan 9, 2025 | The <redacted>.so library, which is used by <redacted>, is vulnerable to a buffer overflow in the code that handles the ... |
| CVE-2024-43660 | HIGH | 7.5 | 0.6% | Jan 9, 2025 | The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware ... |
| CVE-2024-43659 | HIGH | 8.3 | 0.8% | Jan 9, 2025 | After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default crede... |
| CVE-2024-43658 | HIGH | 7.2 | 0.5% | Jan 9, 2025 | Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary fil... |
| CVE-2024-43657 | CRITICAL | 9.3 | 1.4% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43656 | CRITICAL | 9.3 | 1.5% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43655 | CRITICAL | 9.3 | 1.2% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43654 | CRITICAL | 9.3 | 2.1% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware... |
| CVE-2024-43653 | CRITICAL | 9.3 | 2.1% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inj... |
| CVE-2024-43652 | CRITICAL | 9.3 | 1.9% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43651 | CRITICAL | 9.3 | 1.7% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now