2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44843 | MEDIUM | 5.9 | 0.4% | Apr 15, 2025 | An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbit... |
| CVE-2024-42200 | MEDIUM | 5.4 | 0.2% | Apr 15, 2025 | HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validat... |
| CVE-2024-42189 | MEDIUM | 6.5 | 0.2% | Apr 15, 2025 | HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an ... |
| CVE-2024-13177 | MEDIUM | 5.2 | 0.1% | Apr 15, 2025 | Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the ... |
| CVE-2024-11084 | MEDIUM | 6.3 | 0.4% | Apr 15, 2025 | Helix ALM prior to 2025.1 returns distinct error responses during authentication, allowing an attacker to determine whet... |
| CVE-2024-45712 | MEDIUM | 5.4 | 0.3% | Apr 15, 2025 | SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be... |
| CVE-2024-13610 | MEDIUM | 4.8 | 0.2% | Apr 15, 2025 | The Simple Social Media Share Buttons WordPress plugin before 6.0.0 does not sanitise and escape some of its settings, ... |
| CVE-2024-13207 | MEDIUM | 4.8 | 0.2% | Apr 15, 2025 | The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which ... |
| CVE-2024-49825 | MEDIUM | 4.3 | 0.2% | Apr 14, 2025 | IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through ... |
| CVE-2024-49709 | MEDIUM | 4.4 | 0.2% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attack... |
| CVE-2024-49708 | MEDIUM | 5.4 | 0.2% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An ... |
| CVE-2024-49707 | MEDIUM | 6.1 | 0.2% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ... |
| CVE-2024-49706 | MEDIUM | 6.1 | 0.3% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 enco... |
| CVE-2024-49705 | MEDIUM | 6.5 | 0.3% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. A... |
| CVE-2024-13598 | MEDIUM | 6.1 | 0.2% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks.... |
| CVE-2024-13597 | MEDIUM | 5.1 | 0.3% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ... |
| CVE-2024-10090 | MEDIUM | 6.1 | 0.2% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ... |
| CVE-2024-10089 | MEDIUM | 5.4 | 0.2% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An ... |
| CVE-2024-10088 | MEDIUM | 6.1 | 0.2% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ... |
| CVE-2024-10087 | MEDIUM | 5.4 | 0.2% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ... |
| CVE-2024-9230 | MEDIUM | 5.9 | 0.2% | Apr 14, 2025 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set... |
| CVE-2024-13338 | MEDIUM | 4.3 | 0.1% | Apr 12, 2025 | The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr... |
| CVE-2024-13337 | MEDIUM | 4.3 | 0.2% | Apr 12, 2025 | The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr... |
| CVE-2024-11679 | MEDIUM | 6.7 | 0.1% | Apr 11, 2025 | An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could all... |
| CVE-2024-52282 | MEDIUM | 6.2 | 0.4% | Apr 11, 2025 | A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now