2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9017 | MEDIUM | 6.4 | 0.2% | Jul 3, 2025 | The PeepSo Core: Groups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Group Description fiel... |
| CVE-2024-35164 | HIGH | 7.5 | 0.4% | Jul 2, 2025 | The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers... |
| CVE-2024-13786 | CRITICAL | 9.8 | 0.5% | Jul 2, 2025 | The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via... |
| CVE-2024-13451 | HIGH | 7.5 | 0.3% | Jul 2, 2025 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
| CVE-2024-11405 | MEDIUM | 6.1 | 0.2% | Jul 2, 2025 | The WP Front-end login and register plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the email a... |
| CVE-2024-49365 | HIGH | 8.1 | 0.2% | Jul 1, 2025 | tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can... |
| CVE-2024-49364 | HIGH | 8.1 | 0.3% | Jul 1, 2025 | tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing ... |
| CVE-2024-46993 | MEDIUM | 4.4 | 0.1% | Jul 1, 2025 | Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In ... |
| CVE-2024-46992 | HIGH | 7.8 | 0.1% | Jul 1, 2025 | Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Fro... |
| CVE-2024-12915 | MEDIUM | 4.6 | 0.2% | Jun 30, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Devinim Sof... |
| CVE-2024-53621 | HIGH | 7.5 | 0.4% | Jun 30, 2025 | A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allow... |
| CVE-2024-8419 | HIGH | 7.5 | 0.4% | Jun 30, 2025 | The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the ... |
| CVE-2024-24915 | HIGH | 7.2 | 0.2% | Jun 29, 2025 | Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump ... |
| CVE-2024-52900 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | IBM Cognos Analytics 11.2.0 through 12.2.4 Fix Pack 5 and 12.0.0 through 12.0.4 is vulnerable to stored cross-site scrip... |
| CVE-2024-39730 | MEDIUM | 5.4 | 0.2% | Jun 28, 2025 | IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the victim.... |
| CVE-2024-36347 | MEDIUM | 6.4 | 0.1% | Jun 27, 2025 | Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri... |
| CVE-2024-12364 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Softwar... |
| CVE-2024-12150 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Woww... |
| CVE-2024-12143 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile In... |
| CVE-2024-11739 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics C... |
| CVE-2024-12827 | CRITICAL | 9.8 | 0.4% | Jun 27, 2025 | The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take... |
| CVE-2024-52928 | HIGH | 8.3 | 0.4% | Jun 26, 2025 | Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permi... |
| CVE-2024-56915 | MEDIUM | 6.5 | 0.4% | Jun 26, 2025 | Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget. |
| CVE-2024-6174 | HIGH | 8.8 | 0.2% | Jun 26, 2025 | When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To preven... |
| CVE-2024-11584 | MEDIUM | 5.3 | 0.1% | Jun 26, 2025 | cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grant... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now