2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12368 | HIGH | 8.8 | 0.6% | Feb 25, 2025 | Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user... |
| CVE-2024-12918 | HIGH | 8.8 | 0.4% | Feb 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Hea... |
| CVE-2024-12917 | HIGH | 8.3 | 0.4% | Feb 24, 2025 | Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorre... |
| CVE-2024-12916 | HIGH | 8.8 | 0.4% | Feb 24, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Lif... |
| CVE-2024-55898 | HIGH | 8.5 | 0.4% | Feb 24, 2025 | IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated pri... |
| CVE-2024-52939 | HIGH | 7.8 | 0.2% | Feb 22, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ... |
| CVE-2024-46975 | HIGH | 7.9 | 0.1% | Feb 22, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data in... |
| CVE-2024-12577 | HIGH | 7.3 | 0.2% | Feb 22, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou... |
| CVE-2024-13869 | HIGH | 7.2 | 2.1% | Feb 22, 2025 | The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads... |
| CVE-2024-13474 | HIGH | 7.5 | 0.4% | Feb 22, 2025 | The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id... |
| CVE-2024-13899 | HIGH | 7.2 | 0.6% | Feb 22, 2025 | The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 ... |
| CVE-2024-22341 | HIGH | 7.5 | 0.4% | Feb 22, 2025 | IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.... |
| CVE-2024-57176 | HIGH | 7.6 | 0.5% | Feb 21, 2025 | An issue in the shiroFilter function of White-Jotter project v0.2.2 allows attackers to execute a directory traversal an... |
| CVE-2024-9150 | HIGH | 8.7 | 0.4% | Feb 21, 2025 | Report generation functionality in Wyn Enterprise allows for code inclusion, but not sufficiently limits what code might... |
| CVE-2024-13900 | HIGH | 7.2 | 0.4% | Feb 21, 2025 | The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and... |
| CVE-2024-13353 | HIGH | 8.8 | 0.7% | Feb 21, 2025 | The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne... |
| CVE-2024-11260 | HIGH | 7.5 | 0.6% | Feb 21, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injecti... |
| CVE-2024-13818 | HIGH | 7.5 | 0.5% | Feb 21, 2025 | The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & C... |
| CVE-2024-46933 | HIGH | 7.7 | 0.4% | Feb 20, 2025 | An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH ... |
| CVE-2024-57716 | HIGH | 7.5 | 0.5% | Feb 20, 2025 | An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselecta... |
| CVE-2024-49781 | HIGH | 7.1 | 0.4% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when ... |
| CVE-2024-49779 | HIGH | 8.8 | 0.2% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, cau... |
| CVE-2024-13753 | HIGH | 8.8 | 0.2% | Feb 20, 2025 | The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2024-13476 | HIGH | 7.5 | 0.4% | Feb 20, 2025 | The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to SQL Injection via the 'engtz_wd_save_... |
| CVE-2024-49782 | HIGH | 8.2 | 0.3% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 could allow a remote attacker to spoof mail server identity when using SSL/TLS... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now