2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10087 | MEDIUM | 5.4 | 0.2% | Apr 14, 2025 | Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. ... |
| CVE-2024-9230 | MEDIUM | 5.9 | 0.2% | Apr 14, 2025 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its set... |
| CVE-2024-13338 | MEDIUM | 4.3 | 0.1% | Apr 12, 2025 | The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr... |
| CVE-2024-13337 | MEDIUM | 4.3 | 0.2% | Apr 12, 2025 | The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cr... |
| CVE-2024-11679 | MEDIUM | 6.7 | 0.1% | Apr 11, 2025 | An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could all... |
| CVE-2024-52282 | MEDIUM | 6.2 | 0.4% | Apr 11, 2025 | A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET ... |
| CVE-2024-51461 | MEDIUM | 6.5 | 0.3% | Apr 11, 2025 | IBM QRadar WinCollect Agent 10.0 through 10.1.13 could allow a remote attacker to cause a denial of service by interrupt... |
| CVE-2024-13909 | MEDIUM | 4.9 | 0.2% | Apr 10, 2025 | The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderb... |
| CVE-2024-13896 | MEDIUM | 6.5 | 0.4% | Apr 10, 2025 | The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-... |
| CVE-2024-10894 | MEDIUM | 6.4 | 0.3% | Apr 10, 2025 | The Payment Forms for Paystack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortc... |
| CVE-2024-8243 | MEDIUM | 6.3 | 0.1% | Apr 9, 2025 | The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and i... |
| CVE-2024-6860 | MEDIUM | 4.3 | 0.2% | Apr 9, 2025 | The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix setting... |
| CVE-2024-6857 | MEDIUM | 4.3 | 0.2% | Apr 9, 2025 | The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body ... |
| CVE-2024-52980 | MEDIUM | 6.5 | 0.4% | Apr 8, 2025 | A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the ... |
| CVE-2024-52974 | MEDIUM | 6.5 | 0.3% | Apr 8, 2025 | An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana serve... |
| CVE-2024-54025 | MEDIUM | 6.7 | 0.4% | Apr 8, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-52962 | MEDIUM | 5.3 | 0.4% | Apr 8, 2025 | An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4... |
| CVE-2024-32122 | MEDIUM | 4.4 | 0.2% | Apr 8, 2025 | A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7... |
| CVE-2024-41796 | MEDIUM | 6.9 | 0.3% | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de... |
| CVE-2024-41795 | MEDIUM | 6.9 | 0.2% | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de... |
| CVE-2024-41791 | MEDIUM | 6.5 | 0.3% | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de... |
| CVE-2024-47261 | MEDIUM | 4.3 | 0.3% | Apr 8, 2025 | 51l3nc3, a member of the AXIS OS Bug Bounty Program, has found that the VAPIX API uploadoverlayimage.cgi did not have su... |
| CVE-2024-13820 | MEDIUM | 5.3 | 0.3% | Apr 8, 2025 | The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2024-46494 | MEDIUM | 5.4 | 0.2% | Apr 7, 2025 | A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2024-38797 | MEDIUM | 4.6 | 0.2% | Apr 7, 2025 | EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data po... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now