2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8314 | MEDIUM | 5.5 | 0.3% | Mar 25, 2025 | An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in ... |
| CVE-2024-10208 | MEDIUM | 5.1 | 0.4% | Mar 25, 2025 | An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <... |
| CVE-2024-10207 | MEDIUM | 5.3 | 0.3% | Mar 25, 2025 | A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticat... |
| CVE-2024-10206 | MEDIUM | 6.9 | 0.4% | Mar 25, 2025 | A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthentic... |
| CVE-2024-9103 | MEDIUM | 6.1 | 0.2% | Mar 24, 2025 | Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messag... |
| CVE-2024-55279 | MEDIUM | 6 | 0.3% | Mar 24, 2025 | Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files. |
| CVE-2024-13666 | MEDIUM | 5.3 | 0.3% | Mar 22, 2025 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2024-13856 | MEDIUM | 6.4 | 0.3% | Mar 22, 2025 | The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Fo... |
| CVE-2024-13768 | MEDIUM | 4.3 | 0.1% | Mar 22, 2025 | The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-S... |
| CVE-2024-13739 | MEDIUM | 6.1 | 0.2% | Mar 22, 2025 | The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versi... |
| CVE-2024-13737 | MEDIUM | 4.3 | 0.3% | Mar 22, 2025 | The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2024-50053 | MEDIUM | 5.4 | 1.0% | Mar 21, 2025 | Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below... |
| CVE-2024-54564 | MEDIUM | 6.5 | 0.3% | Mar 21, 2025 | This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonom... |
| CVE-2024-48591 | MEDIUM | 6.1 | 0.4% | Mar 20, 2025 | Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded tha... |
| CVE-2024-13923 | MEDIUM | 6.5 | 0.4% | Mar 20, 2025 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all... |
| CVE-2024-13922 | MEDIUM | 6.5 | 0.4% | Mar 20, 2025 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to ins... |
| CVE-2024-13920 | MEDIUM | 4.9 | 0.7% | Mar 20, 2025 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all version... |
| CVE-2024-13558 | MEDIUM | 5.3 | 0.3% | Mar 20, 2025 | The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi... |
| CVE-2024-9900 | MEDIUM | 6.1 | 0.5% | Mar 20, 2025 | mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vuln... |
| CVE-2024-9699 | MEDIUM | 5.4 | 0.3% | Mar 20, 2025 | A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to... |
| CVE-2024-9617 | MEDIUM | 6.5 | 1.6% | Mar 20, 2025 | An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verif... |
| CVE-2024-9612 | MEDIUM | 6.5 | 0.7% | Mar 20, 2025 | In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search p... |
| CVE-2024-9447 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisat... |
| CVE-2024-9418 | MEDIUM | 6.5 | 0.6% | Mar 20, 2025 | In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in ... |
| CVE-2024-9365 | MEDIUM | 6.5 | 0.2% | Mar 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now