2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54179 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | IBM Business Automation Workflow and IBM Business Automation Workflow Enterprise Service Bus 24.0.0, 24.0.1 and earlier ... |
| CVE-2024-53025 | MEDIUM | 5.5 | 0.1% | Mar 3, 2025 | Transient DOS can occur while processing UCI command. |
| CVE-2024-43056 | MEDIUM | 6.5 | 0.1% | Mar 3, 2025 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. |
| CVE-2024-43051 | MEDIUM | 5.5 | 0.1% | Mar 3, 2025 | Information disclosure while deriving keys for a session for any Widevine use case. |
| CVE-2024-38426 | MEDIUM | 5.3 | 0.2% | Mar 3, 2025 | While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| CVE-2024-24778 | MEDIUM | 6.5 | 0.6% | Mar 3, 2025 | Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resou... |
| CVE-2024-10925 | MEDIUM | 5.3 | 0.3% | Mar 3, 2025 | A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 1... |
| CVE-2024-8186 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17.... |
| CVE-2024-53386 | MEDIUM | 6.1 | 0.2% | Mar 3, 2025 | Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not di... |
| CVE-2024-53382 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but ... |
| CVE-2024-36353 | MEDIUM | 6.5 | 0.1% | Mar 2, 2025 | Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over mem... |
| CVE-2024-55907 | MEDIUM | 5.3 | 0.2% | Mar 2, 2025 | IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain kno... |
| CVE-2024-41778 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, whi... |
| CVE-2024-13546 | MEDIUM | 4.3 | 0.3% | Mar 1, 2025 | The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu... |
| CVE-2024-13697 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu... |
| CVE-2024-13806 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl... |
| CVE-2024-13901 | MEDIUM | 4.8 | 0.3% | Mar 1, 2025 | The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to... |
| CVE-2024-9217 | MEDIUM | 6.1 | 0.3% | Mar 1, 2025 | The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us... |
| CVE-2024-9212 | MEDIUM | 6.1 | 0.3% | Mar 1, 2025 | The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of... |
| CVE-2024-13750 | MEDIUM | 6.5 | 0.4% | Mar 1, 2025 | The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'or... |
| CVE-2024-13746 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss ... |
| CVE-2024-13559 | MEDIUM | 6.4 | 0.2% | Mar 1, 2025 | The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wis... |
| CVE-2024-13518 | MEDIUM | 4.3 | 0.2% | Mar 1, 2025 | The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-13358 | MEDIUM | 4.3 | 0.2% | Mar 1, 2025 | The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to... |
| CVE-2024-54175 | MEDIUM | 5.5 | 0.1% | Feb 28, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now