2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56195 | MEDIUM | 6.3 | 0.7% | Mar 6, 2025 | Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 th... |
| CVE-2024-38311 | MEDIUM | 6.3 | 0.8% | Mar 6, 2025 | Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 ... |
| CVE-2024-56202 | MEDIUM | 4.3 | 0.8% | Mar 6, 2025 | Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.... |
| CVE-2024-13902 | MEDIUM | 5.4 | 0.3% | Mar 6, 2025 | A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown ... |
| CVE-2024-13897 | MEDIUM | 6.5 | 0.9% | Mar 6, 2025 | The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val... |
| CVE-2024-13868 | MEDIUM | 6.1 | 0.3% | Mar 6, 2025 | The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise an... |
| CVE-2024-48246 | MEDIUM | 5.4 | 0.4% | Mar 5, 2025 | Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /veh... |
| CVE-2024-13423 | MEDIUM | 5.3 | 0.4% | Mar 5, 2025 | The Sparkling theme for WordPress is vulnerable to unauthorized plugin activation/deactivation due to a missing capabili... |
| CVE-2024-12650 | MEDIUM | 5.4 | 0.3% | Mar 5, 2025 | An attacker with low privileges can manipulate the requested memory size, causing the application to use an invalid memo... |
| CVE-2024-11153 | MEDIUM | 5.3 | 0.4% | Mar 5, 2025 | The Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More plugin... |
| CVE-2024-5667 | MEDIUM | 6.4 | 0.3% | Mar 5, 2025 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Featherlight.js Ja... |
| CVE-2024-13839 | MEDIUM | 6.1 | 0.3% | Mar 5, 2025 | The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t... |
| CVE-2024-13815 | MEDIUM | 6.5 | 0.3% | Mar 5, 2025 | The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including... |
| CVE-2024-13811 | MEDIUM | 4.3 | 0.2% | Mar 5, 2025 | The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthoriz... |
| CVE-2024-13810 | MEDIUM | 4.3 | 0.2% | Mar 5, 2025 | The Zass - WooCommerce Theme for Handmade Artists and Artisans theme for WordPress is vulnerable to unauthorized access ... |
| CVE-2024-13809 | MEDIUM | 6.5 | 0.3% | Mar 5, 2025 | The Hero Slider - WordPress Slider Plugin plugin for WordPress is vulnerable to SQL Injection via several parameters in ... |
| CVE-2024-13780 | MEDIUM | 6.5 | 0.3% | Mar 5, 2025 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due ... |
| CVE-2024-13779 | MEDIUM | 6.1 | 0.2% | Mar 5, 2025 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripti... |
| CVE-2024-13778 | MEDIUM | 6.5 | 0.3% | Mar 5, 2025 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to SQL Injection via several fu... |
| CVE-2024-13757 | MEDIUM | 5.4 | 0.3% | Mar 5, 2025 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-13747 | MEDIUM | 4.3 | 0.2% | Mar 5, 2025 | The WooMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized loss of data due to a miss... |
| CVE-2024-12815 | MEDIUM | 6.4 | 0.3% | Mar 5, 2025 | The Point Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'point_maker' shortco... |
| CVE-2024-11731 | MEDIUM | 5.4 | 0.3% | Mar 5, 2025 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-8682 | MEDIUM | 5.3 | 0.3% | Mar 5, 2025 | The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registrat... |
| CVE-2024-13866 | MEDIUM | 6.4 | 0.2% | Mar 5, 2025 | The Simple Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now