2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53386 | MEDIUM | 6.1 | 0.2% | Mar 3, 2025 | Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not di... |
| CVE-2024-53382 | MEDIUM | 5.4 | 0.3% | Mar 3, 2025 | Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but ... |
| CVE-2024-36353 | MEDIUM | 6.5 | 0.1% | Mar 2, 2025 | Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over mem... |
| CVE-2024-55907 | MEDIUM | 5.3 | 0.2% | Mar 2, 2025 | IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain kno... |
| CVE-2024-41778 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, whi... |
| CVE-2024-13546 | MEDIUM | 4.3 | 0.3% | Mar 1, 2025 | The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu... |
| CVE-2024-13697 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu... |
| CVE-2024-13806 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl... |
| CVE-2024-13901 | MEDIUM | 4.8 | 0.3% | Mar 1, 2025 | The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to... |
| CVE-2024-9217 | MEDIUM | 6.1 | 0.3% | Mar 1, 2025 | The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us... |
| CVE-2024-9212 | MEDIUM | 6.1 | 0.3% | Mar 1, 2025 | The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of... |
| CVE-2024-13750 | MEDIUM | 6.5 | 0.4% | Mar 1, 2025 | The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'or... |
| CVE-2024-13746 | MEDIUM | 6.5 | 0.3% | Mar 1, 2025 | The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss ... |
| CVE-2024-13559 | MEDIUM | 6.4 | 0.2% | Mar 1, 2025 | The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wis... |
| CVE-2024-13518 | MEDIUM | 4.3 | 0.2% | Mar 1, 2025 | The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-13358 | MEDIUM | 4.3 | 0.2% | Mar 1, 2025 | The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to... |
| CVE-2024-54175 | MEDIUM | 5.5 | 0.1% | Feb 28, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper c... |
| CVE-2024-44754 | MEDIUM | 6.8 | 0.2% | Feb 28, 2025 | Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate at... |
| CVE-2024-10860 | MEDIUM | 4.3 | 0.2% | Feb 28, 2025 | The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data... |
| CVE-2024-9019 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-13851 | MEDIUM | 4.8 | 0.2% | Feb 28, 2025 | The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi... |
| CVE-2024-13832 | MEDIUM | 4.3 | 0.3% | Feb 28, 2025 | The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an... |
| CVE-2024-13716 | MEDIUM | 4.3 | 0.3% | Feb 28, 2025 | The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-13469 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link i... |
| CVE-2024-12820 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' short... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now