2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13669 | MEDIUM | 6.1 | 0.4% | Feb 26, 2025 | The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-13634 | MEDIUM | 6.1 | 0.6% | Feb 26, 2025 | The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-13630 | MEDIUM | 6.1 | 0.6% | Feb 26, 2025 | The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13629 | MEDIUM | 6.1 | 0.4% | Feb 26, 2025 | The pushBIZ WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page... |
| CVE-2024-13628 | MEDIUM | 6.1 | 0.6% | Feb 26, 2025 | The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2024-13560 | MEDIUM | 4.3 | 0.3% | Feb 26, 2025 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi... |
| CVE-2024-13113 | MEDIUM | 5.9 | 0.3% | Feb 26, 2025 | The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when output... |
| CVE-2024-12737 | MEDIUM | 6.1 | 0.6% | Feb 26, 2025 | The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a pa... |
| CVE-2024-12434 | MEDIUM | 5.3 | 0.5% | Feb 26, 2025 | The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2024-10563 | MEDIUM | 5.4 | 0.3% | Feb 26, 2025 | The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode at... |
| CVE-2024-27246 | MEDIUM | 6.5 | 0.6% | Feb 25, 2025 | Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via n... |
| CVE-2024-27245 | MEDIUM | 6.5 | 0.6% | Feb 25, 2025 | Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via ... |
| CVE-2024-27239 | MEDIUM | 6.5 | 0.6% | Feb 25, 2025 | Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via n... |
| CVE-2024-45426 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclos... |
| CVE-2024-45425 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure v... |
| CVE-2024-45417 | MEDIUM | 5.5 | 0.2% | Feb 25, 2025 | Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privile... |
| CVE-2024-36259 | MEDIUM | 6.5 | 0.6% | Feb 25, 2025 | Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attac... |
| CVE-2024-11955 | MEDIUM | 6.1 | 0.5% | Feb 25, 2025 | A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is ... |
| CVE-2024-54444 | MEDIUM | 5.4 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento... |
| CVE-2024-34036 | MEDIUM | 4.3 | 0.2% | Feb 25, 2025 | An issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the... |
| CVE-2024-34035 | MEDIUM | 5.7 | 0.2% | Feb 25, 2025 | An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must fl... |
| CVE-2024-34034 | MEDIUM | 5.7 | 0.2% | Feb 25, 2025 | An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, trigg... |
| CVE-2024-13695 | MEDIUM | 5.4 | 0.2% | Feb 25, 2025 | The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 ... |
| CVE-2024-13693 | MEDIUM | 5.3 | 0.3% | Feb 25, 2025 | The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-ex... |
| CVE-2024-13494 | MEDIUM | 4.3 | 0.2% | Feb 25, 2025 | The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now