2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54446 | HIGH | 7.1 | 0.3% | Mar 14, 2025 | Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a ... |
| CVE-2024-54445 | HIGH | 8.7 | 0.3% | Mar 14, 2025 | Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-base... |
| CVE-2024-12245 | HIGH | 8.7 | 0.3% | Mar 14, 2025 | Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-bas... |
| CVE-2024-12019 | HIGH | 7.1 | 0.4% | Mar 14, 2025 | The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read... |
| CVE-2024-46662 | HIGH | 8.8 | 2.1% | Mar 14, 2025 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions ... |
| CVE-2024-45643 | HIGH | 7.5 | 0.2% | Mar 14, 2025 | IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt ... |
| CVE-2024-13773 | HIGH | 7.5 | 0.3% | Mar 14, 2025 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information... |
| CVE-2024-12810 | HIGH | 8.1 | 0.3% | Mar 14, 2025 | The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modificat... |
| CVE-2024-8176 | HIGH | 7.5 | 1.6% | Mar 14, 2025 | A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XM... |
| CVE-2024-13913 | HIGH | 8.8 | 2.4% | Mar 14, 2025 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2024-13376 | HIGH | 8.8 | 0.3% | Mar 14, 2025 | The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat... |
| CVE-2024-11283 | HIGH | 7.5 | 0.4% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th... |
| CVE-2024-55549 | HIGH | 7.8 | 0.3% | Mar 14, 2025 | xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. |
| CVE-2024-53406 | HIGH | 8.8 | 0.6% | Mar 13, 2025 | Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection p... |
| CVE-2024-10942 | HIGH | 7.5 | 0.5% | Mar 13, 2025 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,... |
| CVE-2024-8402 | HIGH | 7.4 | 0.2% | Mar 13, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from... |
| CVE-2024-13891 | HIGH | 7.1 | 0.3% | Mar 13, 2025 | The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13885 | HIGH | 7.1 | 0.3% | Mar 13, 2025 | The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2024-13884 | HIGH | 7.1 | 0.3% | Mar 13, 2025 | The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-12380 | HIGH | 7.5 | 0.5% | Mar 13, 2025 | An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting f... |
| CVE-2024-26290 | HIGH | 8.7 | 0.5% | Mar 12, 2025 | Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Av... |
| CVE-2024-13872 | HIGH | 7.5 | 0.2% | Mar 12, 2025 | Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Int... |
| CVE-2024-13871 | HIGH | 8.8 | 0.8% | Mar 12, 2025 | A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (fir... |
| CVE-2024-58087 | HIGH | 8.1 | 0.4% | Mar 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expir... |
| CVE-2024-9157 | HIGH | 7.8 | 0.3% | Mar 11, 2025 | ** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now