2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13418 | HIGH | 8.8 | 0.6% | May 2, 2025 | Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check ... |
| CVE-2024-13344 | HIGH | 7.5 | 0.3% | May 2, 2025 | The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'pro... |
| CVE-2024-13322 | HIGH | 7.5 | 1.6% | May 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via... |
| CVE-2024-12023 | MEDIUM | 6.5 | 0.3% | May 2, 2025 | The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.5 ... |
| CVE-2024-55913 | MEDIUM | 5.3 | 0.4% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 could allow a remote attacker to traverse directories on the system. An attacke... |
| CVE-2024-55912 | MEDIUM | 5.9 | 0.2% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker... |
| CVE-2024-55910 | MEDIUM | 6.5 | 0.2% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenti... |
| CVE-2024-55909 | MEDIUM | 6.5 | 0.3% | May 2, 2025 | IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expan... |
| CVE-2024-52903 | HIGH | 7.5 | 0.3% | May 1, 2025 | IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under... |
| CVE-2024-48907 | HIGH | 7.5 | 0.4% | May 1, 2025 | Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API. |
| CVE-2024-48906 | MEDIUM | 6.1 | 0.2% | May 1, 2025 | Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name. |
| CVE-2024-48905 | CRITICAL | 9.1 | 0.4% | May 1, 2025 | Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint. |
| CVE-2024-52979 | HIGH | 7.5 | 0.5% | May 1, 2025 | Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache ... |
| CVE-2024-52976 | HIGH | 7.8 | 0.2% | May 1, 2025 | Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attacker... |
| CVE-2024-11994 | MEDIUM | 5.7 | 0.2% | May 1, 2025 | APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the na... |
| CVE-2024-11390 | MEDIUM | 5.4 | 0.3% | May 1, 2025 | Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s bro... |
| CVE-2024-13381 | MEDIUM | 4.8 | 0.2% | May 1, 2025 | The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could... |
| CVE-2024-13845 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ... |
| CVE-2024-30146 | LOW | 2.7 | 0.2% | Apr 30, 2025 | Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server... |
| CVE-2024-30145 | MEDIUM | 6.1 | 0.2% | Apr 30, 2025 | Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and ... |
| CVE-2024-30115 | MEDIUM | 5.4 | 0.2% | Apr 30, 2025 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the... |
| CVE-2024-6032 | HIGH | 7.8 | 0.5% | Apr 30, 2025 | Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attack... |
| CVE-2024-6031 | HIGH | 7.8 | 0.2% | Apr 30, 2025 | Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local ... |
| CVE-2024-6030 | HIGH | 7 | 0.1% | Apr 30, 2025 | Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to es... |
| CVE-2024-6029 | MEDIUM | 5 | 0.2% | Apr 30, 2025 | Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attack... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now