2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57685 | MEDIUM | 5.3 | 0.4% | Feb 24, 2025 | An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file. |
| CVE-2024-53543 | MEDIUM | 5.4 | 0.2% | Feb 24, 2025 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability... |
| CVE-2024-53542 | MEDIUM | 6.5 | 0.2% | Feb 24, 2025 | Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Tim... |
| CVE-2024-57608 | MEDIUM | 6.5 | 0.4% | Feb 24, 2025 | An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component. |
| CVE-2024-57026 | MEDIUM | 6.1 | 0.4% | Feb 24, 2025 | TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that al... |
| CVE-2024-5174 | MEDIUM | 5.3 | 0.3% | Feb 24, 2025 | A flaw in Gliffy results in broken authentication through the reset functionality of the application. |
| CVE-2024-13822 | MEDIUM | 6.1 | 0.3% | Feb 24, 2025 | The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter... |
| CVE-2024-13605 | MEDIUM | 4.8 | 0.3% | Feb 24, 2025 | The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-12308 | MEDIUM | 5.4 | 0.3% | Feb 24, 2025 | The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outp... |
| CVE-2024-13728 | MEDIUM | 6.1 | 0.3% | Feb 23, 2025 | The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the r... |
| CVE-2024-13564 | MEDIUM | 5.4 | 0.3% | Feb 22, 2025 | The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2024-13798 | MEDIUM | 5.3 | 0.3% | Feb 22, 2025 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in al... |
| CVE-2024-12467 | MEDIUM | 6.1 | 0.3% | Feb 22, 2025 | The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters'... |
| CVE-2024-12038 | MEDIUM | 5.4 | 0.2% | Feb 22, 2025 | The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p... |
| CVE-2024-13873 | MEDIUM | 4.3 | 0.3% | Feb 22, 2025 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to... |
| CVE-2024-55159 | MEDIUM | 4.2 | 0.2% | Feb 21, 2025 | GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/l... |
| CVE-2024-55156 | MEDIUM | 5.5 | 0.2% | Feb 21, 2025 | An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows att... |
| CVE-2024-45673 | MEDIUM | 5.5 | 0.1% | Feb 21, 2025 | IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 thro... |
| CVE-2024-10222 | MEDIUM | 5.4 | 0.4% | Feb 21, 2025 | The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u... |
| CVE-2024-13846 | MEDIUM | 4.9 | 0.4% | Feb 21, 2025 | The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parame... |
| CVE-2024-13713 | MEDIUM | 6.5 | 0.4% | Feb 21, 2025 | The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all vers... |
| CVE-2024-13455 | MEDIUM | 5.4 | 0.2% | Feb 21, 2025 | The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_cal... |
| CVE-2024-13648 | MEDIUM | 5.4 | 0.3% | Feb 21, 2025 | The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortco... |
| CVE-2024-13461 | MEDIUM | 5.4 | 0.2% | Feb 21, 2025 | The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2024-12452 | MEDIUM | 5.4 | 0.3% | Feb 21, 2025 | The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now