2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13941 | MEDIUM | 5.3 | 0.2% | Apr 1, 2025 | A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ou... |
| CVE-2024-12278 | MEDIUM | 6.1 | 0.3% | Apr 1, 2025 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typi... |
| CVE-2024-12189 | MEDIUM | 6.4 | 0.2% | Apr 1, 2025 | The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPres... |
| CVE-2024-24456 | MEDIUM | 5.9 | 0.3% | Mar 31, 2025 | An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentia... |
| CVE-2024-55093 | MEDIUM | 4.7 | 0.2% | Mar 31, 2025 | phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts. |
| CVE-2024-55895 | MEDIUM | 5.3 | 0.3% | Mar 29, 2025 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec... |
| CVE-2024-11180 | MEDIUM | 5.4 | 0.2% | Mar 29, 2025 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Tim... |
| CVE-2024-13557 | MEDIUM | 6.5 | 0.3% | Mar 29, 2025 | The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t... |
| CVE-2024-51477 | MEDIUM | 6.5 | 0.3% | Mar 29, 2025 | IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an... |
| CVE-2024-43186 | MEDIUM | 6.5 | 0.2% | Mar 29, 2025 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored ... |
| CVE-2024-58130 | MEDIUM | 6.1 | 0.2% | Mar 28, 2025 | In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization... |
| CVE-2024-58129 | MEDIUM | 4.8 | 0.2% | Mar 28, 2025 | In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and t... |
| CVE-2024-58128 | MEDIUM | 4.8 | 0.2% | Mar 28, 2025 | In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus a... |
| CVE-2024-6875 | MEDIUM | 6.5 | 0.4% | Mar 28, 2025 | A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak ... |
| CVE-2024-39311 | MEDIUM | 5.4 | 0.2% | Mar 28, 2025 | Publify is a self hosted Web publishing platform on Rails. Prior to version 10.0.1 of Publify, corresponding to versions... |
| CVE-2024-12619 | MEDIUM | 6.5 | 0.3% | Mar 28, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.... |
| CVE-2024-10307 | MEDIUM | 5.5 | 0.2% | Mar 28, 2025 | An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17... |
| CVE-2024-55072 | MEDIUM | 5.4 | 0.3% | Mar 27, 2025 | A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ... |
| CVE-2024-58091 | MEDIUM | 5.5 | 0.2% | Mar 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/fbdev-dma: Add shadow buffering for deferred I/... |
| CVE-2024-58090 | MEDIUM | 5.5 | 0.2% | Mar 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: sched/core: Prevent rescheduling when interrupts ar... |
| CVE-2024-56469 | MEDIUM | 6.3 | 0.2% | Mar 27, 2025 | IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 ... |
| CVE-2024-48944 | MEDIUM | 6.5 | 0.6% | Mar 27, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a reques... |
| CVE-2024-45361 | MEDIUM | 6.5 | 0.2% | Mar 27, 2025 | A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation... |
| CVE-2024-45355 | MEDIUM | 5.5 | 0.1% | Mar 27, 2025 | A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida... |
| CVE-2024-45354 | MEDIUM | 4.3 | 0.2% | Mar 27, 2025 | A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper inp... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now