2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44754 | MEDIUM | 6.8 | 0.2% | Feb 28, 2025 | Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate at... |
| CVE-2024-10860 | MEDIUM | 4.3 | 0.2% | Feb 28, 2025 | The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data... |
| CVE-2024-9019 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-13851 | MEDIUM | 4.8 | 0.2% | Feb 28, 2025 | The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi... |
| CVE-2024-13832 | MEDIUM | 4.3 | 0.3% | Feb 28, 2025 | The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an... |
| CVE-2024-13716 | MEDIUM | 4.3 | 0.3% | Feb 28, 2025 | The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-13469 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link i... |
| CVE-2024-12820 | MEDIUM | 5.4 | 0.2% | Feb 28, 2025 | The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' short... |
| CVE-2024-56340 | MEDIUM | 6.5 | 0.7% | Feb 28, 2025 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker... |
| CVE-2024-54173 | MEDIUM | 4.7 | 0.1% | Feb 28, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read ... |
| CVE-2024-38290 | MEDIUM | 5.3 | 0.3% | Feb 27, 2025 | In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met. |
| CVE-2024-58042 | MEDIUM | 5.5 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: rhashtable: Fix potential deadlock by moving schedu... |
| CVE-2024-58022 | MEDIUM | 5.5 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: mailbox: th1520: Fix a NULL vs IS_ERR() bug The de... |
| CVE-2024-54957 | MEDIUM | 6.1 | 0.6% | Feb 27, 2025 | Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permi... |
| CVE-2024-53408 | MEDIUM | 5.4 | 0.3% | Feb 27, 2025 | AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2024-9285 | MEDIUM | 5.3 | 0.4% | Feb 27, 2025 | A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue ... |
| CVE-2024-56812 | MEDIUM | 5.5 | 0.1% | Feb 27, 2025 | IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret... |
| CVE-2024-54170 | MEDIUM | 5.5 | 0.1% | Feb 27, 2025 | IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expression with an ineffi... |
| CVE-2024-54169 | MEDIUM | 6.5 | 0.4% | Feb 27, 2025 | IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a s... |
| CVE-2024-13402 | MEDIUM | 5.4 | 0.2% | Feb 27, 2025 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter ... |
| CVE-2024-13217 | MEDIUM | 4.3 | 0.3% | Feb 27, 2025 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2024-13734 | MEDIUM | 5.4 | 0.3% | Feb 27, 2025 | The Card Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Profi... |
| CVE-2024-5848 | MEDIUM | 6.1 | 0.2% | Feb 27, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper input validation. ... |
| CVE-2024-13907 | MEDIUM | 6.5 | 0.4% | Feb 27, 2025 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Serv... |
| CVE-2024-0392 | MEDIUM | 5.4 | 0.1% | Feb 27, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 d... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now