2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45353 | MEDIUM | 4.3 | 0.1% | Mar 27, 2025 | An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is ca... |
| CVE-2024-55965 | MEDIUM | 6.5 | 0.4% | Mar 26, 2025 | An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development in... |
| CVE-2024-55963 | MEDIUM | 6.5 | 27.7% | Mar 26, 2025 | An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the ... |
| CVE-2024-41643 | MEDIUM | 6.8 | 0.3% | Mar 26, 2025 | An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell log... |
| CVE-2024-13411 | MEDIUM | 6.4 | 0.3% | Mar 26, 2025 | The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in... |
| CVE-2024-13702 | MEDIUM | 5.4 | 0.2% | Mar 26, 2025 | The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-30155 | MEDIUM | 4.3 | 0.2% | Mar 26, 2025 | HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able t... |
| CVE-2024-11847 | MEDIUM | 4.8 | 0.2% | Mar 26, 2025 | The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least ... |
| CVE-2024-55029 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. |
| CVE-2024-55604 | MEDIUM | 4.3 | 0.2% | Mar 25, 2025 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not h... |
| CVE-2024-11499 | MEDIUM | 6.9 | 0.2% | Mar 25, 2025 | A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and auth... |
| CVE-2024-10037 | MEDIUM | 5.9 | 0.3% | Mar 25, 2025 | A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU applicati... |
| CVE-2024-53679 | MEDIUM | 5.4 | 0.5% | Mar 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the ... |
| CVE-2024-13731 | MEDIUM | 6.4 | 0.3% | Mar 25, 2025 | The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-13710 | MEDIUM | 4.3 | 0.1% | Mar 25, 2025 | The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2024-12623 | MEDIUM | 6.4 | 0.3% | Mar 25, 2025 | The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in ... |
| CVE-2024-9770 | MEDIUM | 4.7 | 0.3% | Mar 25, 2025 | The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statem... |
| CVE-2024-13118 | MEDIUM | 4.3 | 0.2% | Mar 25, 2025 | The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers t... |
| CVE-2024-12682 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-12109 | MEDIUM | 4.1 | 0.3% | Mar 25, 2025 | The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter ... |
| CVE-2024-11503 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2024-11273 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape s... |
| CVE-2024-11272 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape s... |
| CVE-2024-10703 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its setti... |
| CVE-2024-10679 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now