2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13445 | MEDIUM | 5.4 | 0.3% | Feb 20, 2025 | The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-49780 | MEDIUM | 6.5 | 0.5% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system.... |
| CVE-2024-49355 | MEDIUM | 6.5 | 0.3% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enab... |
| CVE-2024-43196 | MEDIUM | 4.3 | 0.2% | Feb 20, 2025 | IBM OpenPages with Watson 8.3 and 9.0 application could allow an authenticated user to manipulate data in the Question... |
| CVE-2024-6697 | MEDIUM | 6.5 | 0.3% | Feb 20, 2025 | The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functional... |
| CVE-2024-6696 | MEDIUM | 4.9 | 0.3% | Feb 20, 2025 | The product implements access controls via a policy or other feature with the intention to disable or restrict accesses ... |
| CVE-2024-37363 | MEDIUM | 6.5 | 0.3% | Feb 20, 2025 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (C... |
| CVE-2024-37362 | MEDIUM | 6.3 | 0.3% | Feb 20, 2025 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauth... |
| CVE-2024-37360 | MEDIUM | 4.4 | 0.3% | Feb 19, 2025 | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-... |
| CVE-2024-53974 | MEDIUM | 5.4 | 0.3% | Feb 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-45777 | MEDIUM | 6.7 | 0.2% | Feb 19, 2025 | A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_ge... |
| CVE-2024-45081 | MEDIUM | 6.5 | 0.3% | Feb 19, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modif... |
| CVE-2024-28780 | MEDIUM | 5.9 | 0.2% | Feb 19, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses weaker than expected cr... |
| CVE-2024-28776 | MEDIUM | 5.4 | 0.2% | Feb 19, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This ... |
| CVE-2024-13364 | MEDIUM | 5.3 | 0.4% | Feb 19, 2025 | The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_... |
| CVE-2024-13363 | MEDIUM | 6.1 | 0.3% | Feb 19, 2025 | The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all vers... |
| CVE-2024-13339 | MEDIUM | 5.4 | 0.1% | Feb 19, 2025 | The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2024-13336 | MEDIUM | 4.3 | 0.2% | Feb 19, 2025 | The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2024-13231 | MEDIUM | 5.3 | 0.4% | Feb 19, 2025 | The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2024-13854 | MEDIUM | 4.3 | 0.3% | Feb 19, 2025 | The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions... |
| CVE-2024-13736 | MEDIUM | 6.1 | 0.4% | Feb 19, 2025 | The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWid... |
| CVE-2024-13719 | MEDIUM | 5.3 | 0.4% | Feb 19, 2025 | The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ... |
| CVE-2024-13712 | MEDIUM | 4.9 | 0.5% | Feb 19, 2025 | The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and i... |
| CVE-2024-13711 | MEDIUM | 6.1 | 0.3% | Feb 19, 2025 | The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all vers... |
| CVE-2024-13679 | MEDIUM | 5.4 | 0.3% | Feb 19, 2025 | The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' sh... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now