2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52888 | MEDIUM | 5.4 | 0.2% | Apr 27, 2025 | For an authenticated end-user the portal may run a script while attempting to display a directory or some file's propert... |
| CVE-2024-52887 | MEDIUM | 5.4 | 0.2% | Apr 27, 2025 | Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing... |
| CVE-2024-53636 | CRITICAL | 9.8 | 1.2% | Apr 26, 2025 | An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.... |
| CVE-2024-13812 | MEDIUM | 6.5 | 0.3% | Apr 26, 2025 | The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and... |
| CVE-2024-13808 | HIGH | 8.8 | 0.6% | Apr 26, 2025 | The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i... |
| CVE-2024-30152 | CRITICAL | 9.8 | 0.2% | Apr 25, 2025 | HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain acce... |
| CVE-2024-56156 | CRITICAL | 9 | 0.6% | Apr 25, 2025 | Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypa... |
| CVE-2024-57375 | LOW | 2.4 | 0.2% | Apr 25, 2025 | Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to c... |
| CVE-2024-6199 | HIGH | 7.7 | 0.2% | Apr 25, 2025 | An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS ... |
| CVE-2024-6198 | HIGH | 7.7 | 0.3% | Apr 25, 2025 | The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the ... |
| CVE-2024-11917 | HIGH | 8.1 | 0.4% | Apr 25, 2025 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ... |
| CVE-2024-30127 | LOW | 3.2 | 0.1% | Apr 24, 2025 | Missing "no cache" headers in HCL Leap permits sensitive data to be cached. |
| CVE-2024-30147 | MEDIUM | 6.1 | 0.2% | Apr 24, 2025 | Multiple vectors in HCL Leap allow client-side script injection in the authoring environment and deployed applications. |
| CVE-2024-30114 | MEDIUM | 5.4 | 0.2% | Apr 24, 2025 | Insufficient sanitization in HCL Leap allows client-side script injection in the authoring environment. |
| CVE-2024-30113 | MEDIUM | 5.4 | 0.2% | Apr 24, 2025 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the... |
| CVE-2024-30148 | MEDIUM | 4.1 | 0.2% | Apr 24, 2025 | Improper access control of endpoint in HCL Leap allows certain admin users to import applications from the server's file... |
| CVE-2024-13307 | MEDIUM | 5.3 | 0.2% | Apr 24, 2025 | The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of d... |
| CVE-2024-12244 | MEDIUM | 4.3 | 0.3% | Apr 24, 2025 | An issue has been discovered in access controls could allow users to view certain restricted project information even wh... |
| CVE-2024-22351 | MEDIUM | 6.3 | 0.2% | Apr 23, 2025 | IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user ... |
| CVE-2024-58251 | LOW | 2.5 | 0.2% | Apr 23, 2025 | In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI t... |
| CVE-2024-47829 | MEDIUM | 6.5 | 0.2% | Apr 23, 2025 | pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shorten... |
| CVE-2024-10306 | MEDIUM | 5.4 | 0.3% | Apr 23, 2025 | A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <L... |
| CVE-2024-53569 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System... |
| CVE-2024-53568 | MEDIUM | 5.4 | 0.2% | Apr 22, 2025 | A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4... |
| CVE-2024-33452 | HIGH | 7.7 | 0.7% | Apr 22, 2025 | An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling v... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now