2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39442 | MEDIUM | 6.2 | 0.2% | May 6, 2025 | In sprd ssense service, there is a possible missing permission check. This could lead to local information disclosure wi... |
| CVE-2024-42213 | MEDIUM | 5.3 | 0.3% | May 5, 2025 | HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might... |
| CVE-2024-42212 | MEDIUM | 5.4 | 0.2% | May 5, 2025 | HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request For... |
| CVE-2024-51991 | MEDIUM | 4.9 | 0.3% | May 5, 2025 | October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authen... |
| CVE-2024-11615 | MEDIUM | 5.3 | 0.4% | May 5, 2025 | The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1... |
| CVE-2024-58237 | MEDIUM | 5.5 | 0.2% | May 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet poi... |
| CVE-2024-58100 | MEDIUM | 5.5 | 0.2% | May 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: check changes_pkt_data property for extension ... |
| CVE-2024-58098 | MEDIUM | 5.5 | 0.2% | May 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: track changes_pkt_data property for global fun... |
| CVE-2024-41753 | MEDIUM | 6.1 | 0.2% | May 3, 2025 | IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross... |
| CVE-2024-58135 | MEDIUM | 5.3 | 0.5% | May 3, 2025 | Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate a... |
| CVE-2024-55069 | MEDIUM | 5.3 | 0.3% | May 2, 2025 | ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c. |
| CVE-2024-13860 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ param... |
| CVE-2024-13859 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_... |
| CVE-2024-13858 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘in... |
| CVE-2024-13420 | MEDIUM | 4.3 | 0.2% | May 2, 2025 | Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on ... |
| CVE-2024-13419 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to ... |
| CVE-2024-12023 | MEDIUM | 6.5 | 0.3% | May 2, 2025 | The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.5 ... |
| CVE-2024-55913 | MEDIUM | 5.3 | 0.4% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacke... |
| CVE-2024-55912 | MEDIUM | 5.9 | 0.2% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker... |
| CVE-2024-55910 | MEDIUM | 6.5 | 0.2% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenti... |
| CVE-2024-55909 | MEDIUM | 6.5 | 0.3% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expan... |
| CVE-2024-48906 | MEDIUM | 6.1 | 0.2% | May 1, 2025 | Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name. |
| CVE-2024-11994 | MEDIUM | 5.7 | 0.2% | May 1, 2025 | APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the na... |
| CVE-2024-11390 | MEDIUM | 5.4 | 0.3% | May 1, 2025 | Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s bro... |
| CVE-2024-13381 | MEDIUM | 4.8 | 0.2% | May 1, 2025 | The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now