2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58134 | HIGH | 8.1 | 0.4% | May 3, 2025 | Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC sessio... |
| CVE-2024-41753 | MEDIUM | 6.1 | 0.2% | May 3, 2025 | IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross... |
| CVE-2024-58135 | MEDIUM | 5.3 | 0.5% | May 3, 2025 | Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate a... |
| CVE-2024-13738 | HIGH | 7.3 | 0.4% | May 3, 2025 | The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-55069 | MEDIUM | 5.3 | 0.3% | May 2, 2025 | ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c. |
| CVE-2024-58253 | LOW | 2.9 | 0.1% | May 2, 2025 | In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to inva... |
| CVE-2024-11142 | HIGH | 8.8 | 0.2% | May 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forge... |
| CVE-2024-13860 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ param... |
| CVE-2024-13859 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_... |
| CVE-2024-13858 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘in... |
| CVE-2024-13420 | MEDIUM | 4.3 | 0.2% | May 2, 2025 | Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on ... |
| CVE-2024-13419 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to ... |
| CVE-2024-13418 | HIGH | 8.8 | 0.6% | May 2, 2025 | Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check ... |
| CVE-2024-13344 | HIGH | 7.5 | 0.3% | May 2, 2025 | The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'pro... |
| CVE-2024-13322 | HIGH | 7.5 | 1.6% | May 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via... |
| CVE-2024-12023 | MEDIUM | 6.5 | 0.3% | May 2, 2025 | The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.5 ... |
| CVE-2024-55913 | MEDIUM | 5.3 | 0.4% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacke... |
| CVE-2024-55912 | MEDIUM | 5.9 | 0.2% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker... |
| CVE-2024-55910 | MEDIUM | 6.5 | 0.2% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenti... |
| CVE-2024-55909 | MEDIUM | 6.5 | 0.3% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expan... |
| CVE-2024-52903 | HIGH | 7.5 | 0.3% | May 1, 2025 | IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under... |
| CVE-2024-48907 | HIGH | 7.5 | 0.4% | May 1, 2025 | Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API. |
| CVE-2024-48906 | MEDIUM | 6.1 | 0.2% | May 1, 2025 | Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name. |
| CVE-2024-48905 | CRITICAL | 9.1 | 0.4% | May 1, 2025 | Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint. |
| CVE-2024-52979 | HIGH | 7.5 | 0.5% | May 1, 2025 | Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now