2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12434 | MEDIUM | 5.3 | 0.5% | Feb 26, 2025 | The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2024-10563 | MEDIUM | 5.4 | 0.3% | Feb 26, 2025 | The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode at... |
| CVE-2024-27246 | MEDIUM | 6.5 | 0.6% | Feb 25, 2025 | Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via n... |
| CVE-2024-27245 | MEDIUM | 6.5 | 0.6% | Feb 25, 2025 | Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via ... |
| CVE-2024-27239 | MEDIUM | 6.5 | 0.6% | Feb 25, 2025 | Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via n... |
| CVE-2024-45426 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclos... |
| CVE-2024-45425 | MEDIUM | 6.5 | 0.3% | Feb 25, 2025 | Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure v... |
| CVE-2024-45417 | MEDIUM | 5.5 | 0.2% | Feb 25, 2025 | Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privile... |
| CVE-2024-36259 | MEDIUM | 6.5 | 0.6% | Feb 25, 2025 | Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attac... |
| CVE-2024-11955 | MEDIUM | 6.1 | 0.5% | Feb 25, 2025 | A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is ... |
| CVE-2024-54444 | MEDIUM | 5.4 | 0.3% | Feb 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento... |
| CVE-2024-34036 | MEDIUM | 4.3 | 0.2% | Feb 25, 2025 | An issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the... |
| CVE-2024-34035 | MEDIUM | 5.7 | 0.2% | Feb 25, 2025 | An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must fl... |
| CVE-2024-34034 | MEDIUM | 5.7 | 0.2% | Feb 25, 2025 | An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, trigg... |
| CVE-2024-13695 | MEDIUM | 5.4 | 0.2% | Feb 25, 2025 | The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 ... |
| CVE-2024-13693 | MEDIUM | 5.3 | 0.3% | Feb 25, 2025 | The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-ex... |
| CVE-2024-13494 | MEDIUM | 4.3 | 0.2% | Feb 25, 2025 | The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-57685 | MEDIUM | 5.3 | 0.4% | Feb 24, 2025 | An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file. |
| CVE-2024-53543 | MEDIUM | 5.4 | 0.2% | Feb 24, 2025 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability... |
| CVE-2024-53542 | MEDIUM | 6.5 | 0.2% | Feb 24, 2025 | Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Tim... |
| CVE-2024-57608 | MEDIUM | 6.5 | 0.4% | Feb 24, 2025 | An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component. |
| CVE-2024-57026 | MEDIUM | 6.1 | 0.4% | Feb 24, 2025 | TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that al... |
| CVE-2024-5174 | MEDIUM | 5.3 | 0.3% | Feb 24, 2025 | A flaw in Gliffy results in broken authentication through the reset functionality of the application. |
| CVE-2024-13822 | MEDIUM | 6.1 | 0.3% | Feb 24, 2025 | The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter... |
| CVE-2024-13605 | MEDIUM | 4.8 | 0.3% | Feb 24, 2025 | The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now