2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45781 | MEDIUM | 6.7 | 0.2% | Feb 18, 2025 | A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string... |
| CVE-2024-45776 | MEDIUM | 6.7 | 0.2% | Feb 18, 2025 | When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its ... |
| CVE-2024-45775 | MEDIUM | 5.2 | 0.2% | Feb 18, 2025 | A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for... |
| CVE-2024-57056 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to sys... |
| CVE-2024-57055 | MEDIUM | 5 | 0.2% | Feb 18, 2025 | Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potential... |
| CVE-2024-45774 | MEDIUM | 6.7 | 0.2% | Feb 18, 2025 | A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bou... |
| CVE-2024-56882 | MEDIUM | 5.4 | 0.4% | Feb 18, 2025 | Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role pr... |
| CVE-2024-49589 | MEDIUM | 6.5 | 0.5% | Feb 18, 2025 | Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based... |
| CVE-2024-39328 | MEDIUM | 6.8 | 0.3% | Feb 18, 2025 | Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their ... |
| CVE-2024-13689 | MEDIUM | 6.3 | 0.4% | Feb 18, 2025 | The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including... |
| CVE-2024-13783 | MEDIUM | 4.3 | 0.4% | Feb 18, 2025 | The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in for... |
| CVE-2024-13691 | MEDIUM | 6.5 | 0.4% | Feb 18, 2025 | The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_... |
| CVE-2024-13667 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all v... |
| CVE-2024-13718 | MEDIUM | 4.3 | 0.2% | Feb 18, 2025 | The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-... |
| CVE-2024-13395 | MEDIUM | 5.4 | 0.3% | Feb 18, 2025 | The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode... |
| CVE-2024-13316 | MEDIUM | 5.3 | 0.4% | Feb 18, 2025 | The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin... |
| CVE-2024-13795 | MEDIUM | 4.3 | 0.2% | Feb 18, 2025 | The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ... |
| CVE-2024-13704 | MEDIUM | 6.1 | 0.3% | Feb 18, 2025 | The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' paramet... |
| CVE-2024-13575 | MEDIUM | 5.4 | 0.4% | Feb 18, 2025 | The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-13465 | MEDIUM | 5.4 | 0.3% | Feb 18, 2025 | The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Tabl... |
| CVE-2024-11895 | MEDIUM | 5.4 | 0.4% | Feb 18, 2025 | The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-11376 | MEDIUM | 6.1 | 0.4% | Feb 18, 2025 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin... |
| CVE-2024-13523 | MEDIUM | 5.4 | 0.2% | Feb 18, 2025 | The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2024-45320 | MEDIUM | 6.5 | 0.2% | Feb 18, 2025 | Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier... |
| CVE-2024-13438 | MEDIUM | 4.3 | 0.2% | Feb 18, 2025 | The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now