2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11974 | MEDIUM | 6.1 | 0.4% | Jan 4, 2025 | The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_t... |
| CVE-2024-10932 | HIGH | 8.8 | 0.8% | Jan 4, 2025 | The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.... |
| CVE-2024-55897 | MEDIUM | 4.3 | 0.2% | Jan 3, 2025 | IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookie... |
| CVE-2024-55896 | MEDIUM | 5.4 | 0.2% | Jan 3, 2025 | IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames. This vuln... |
| CVE-2024-12237 | MEDIUM | 4.3 | 0.4% | Jan 3, 2025 | The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in... |
| CVE-2024-11733 | HIGH | 7.3 | 0.5% | Jan 3, 2025 | The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t... |
| CVE-2024-13129 | HIGH | 8.8 | 17.8% | Jan 3, 2025 | A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is th... |
| CVE-2024-56332 | MEDIUM | 5.3 | 0.8% | Jan 3, 2025 | Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions ... |
| CVE-2024-56412 | MEDIUM | 5.4 | 0.4% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56411 | MEDIUM | 5.4 | 0.3% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56410 | MEDIUM | 5.4 | 0.3% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-36613 | MEDIUM | 6.2 | 0.3% | Jan 3, 2025 | FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potent... |
| CVE-2024-35365 | HIGH | 8.8 | 0.7% | Jan 3, 2025 | FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically... |
| CVE-2024-56514 | MEDIUM | 5.3 | 0.7% | Jan 3, 2025 | Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes ... |
| CVE-2024-56513 | HIGH | 8.7 | 0.5% | Jan 3, 2025 | Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes ... |
| CVE-2024-56409 | MEDIUM | 5.4 | 0.3% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56366 | MEDIUM | 5.4 | 0.3% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56365 | MEDIUM | 5.4 | 0.3% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56408 | MEDIUM | 5.4 | 0.4% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56324 | HIGH | 7.1 | 0.8% | Jan 3, 2025 | GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edi... |
| CVE-2024-56322 | HIGH | 7.2 | 0.7% | Jan 3, 2025 | GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hi... |
| CVE-2024-56321 | LOW | 3.8 | 0.5% | Jan 3, 2025 | GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the ... |
| CVE-2024-56320 | HIGH | 8.8 | 0.7% | Jan 3, 2025 | GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to i... |
| CVE-2024-55507 | CRITICAL | 9.8 | 0.6% | Jan 3, 2025 | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e... |
| CVE-2024-5591 | MEDIUM | 4.3 | 0.3% | Jan 3, 2025 | IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detaile... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now