2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25066 | MEDIUM | 4.3 | 0.4% | Feb 17, 2025 | RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting... |
| CVE-2024-13879 | MEDIUM | 5.5 | 0.3% | Feb 17, 2025 | The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2... |
| CVE-2024-47935 | MEDIUM | 6.7 | 0.1% | Feb 17, 2025 | Improper Validation of Integrity Check Value vulnerability in TXOne Networks StellarProtect (Legacy Mode), StellarEnforc... |
| CVE-2024-13627 | MEDIUM | 4.7 | 0.8% | Feb 17, 2025 | The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back ... |
| CVE-2024-13608 | MEDIUM | 4.7 | 0.3% | Feb 17, 2025 | The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statemen... |
| CVE-2024-13603 | MEDIUM | 6.1 | 0.4% | Feb 17, 2025 | The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unaut... |
| CVE-2024-57970 | MEDIUM | 4 | 0.2% | Feb 16, 2025 | libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c v... |
| CVE-2024-13834 | MEDIUM | 5.4 | 0.2% | Feb 15, 2025 | The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordP... |
| CVE-2024-13500 | MEDIUM | 6.5 | 0.4% | Feb 15, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo... |
| CVE-2024-13439 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capab... |
| CVE-2024-10581 | MEDIUM | 4.3 | 0.2% | Feb 15, 2025 | The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2024-13752 | MEDIUM | 6.5 | 0.5% | Feb 15, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo... |
| CVE-2024-13563 | MEDIUM | 5.4 | 0.3% | Feb 15, 2025 | The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password s... |
| CVE-2024-13525 | MEDIUM | 6.5 | 0.4% | Feb 15, 2025 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in ... |
| CVE-2024-13306 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ... |
| CVE-2024-13208 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ... |
| CVE-2024-10405 | MEDIUM | 5.3 | 0.2% | Feb 15, 2025 | Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, ... |
| CVE-2024-57790 | MEDIUM | 5.4 | 0.2% | Feb 14, 2025 | IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in ... |
| CVE-2024-56463 | MEDIUM | 4.8 | 0.2% | Feb 14, 2025 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrar... |
| CVE-2024-57725 | MEDIUM | 6.5 | 5.8% | Feb 14, 2025 | An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value wit... |
| CVE-2024-56477 | MEDIUM | 6.5 | 0.5% | Feb 14, 2025 | IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the syst... |
| CVE-2024-52895 | MEDIUM | 6.5 | 0.4% | Feb 14, 2025 | IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities res... |
| CVE-2024-13791 | MEDIUM | 4.9 | 0.6% | Feb 14, 2025 | Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the down... |
| CVE-2024-13735 | MEDIUM | 5.4 | 0.3% | Feb 14, 2025 | The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable ... |
| CVE-2024-9601 | MEDIUM | 5.4 | 0.3% | Feb 14, 2025 | The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now