2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13500 | MEDIUM | 6.5 | 0.4% | Feb 15, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo... |
| CVE-2024-13439 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capab... |
| CVE-2024-10581 | MEDIUM | 4.3 | 0.2% | Feb 15, 2025 | The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2024-13752 | MEDIUM | 6.5 | 0.5% | Feb 15, 2025 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo... |
| CVE-2024-13563 | MEDIUM | 5.4 | 0.3% | Feb 15, 2025 | The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password s... |
| CVE-2024-13525 | MEDIUM | 6.5 | 0.4% | Feb 15, 2025 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in ... |
| CVE-2024-13306 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ... |
| CVE-2024-13208 | MEDIUM | 4.3 | 0.3% | Feb 15, 2025 | The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ... |
| CVE-2024-10405 | MEDIUM | 5.3 | 0.2% | Feb 15, 2025 | Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, ... |
| CVE-2024-57790 | MEDIUM | 5.4 | 0.2% | Feb 14, 2025 | IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in ... |
| CVE-2024-56463 | MEDIUM | 4.8 | 0.2% | Feb 14, 2025 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrar... |
| CVE-2024-57725 | MEDIUM | 6.5 | 5.8% | Feb 14, 2025 | An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value wit... |
| CVE-2024-56477 | MEDIUM | 6.5 | 0.5% | Feb 14, 2025 | IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the syst... |
| CVE-2024-52895 | MEDIUM | 6.5 | 0.4% | Feb 14, 2025 | IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities res... |
| CVE-2024-13791 | MEDIUM | 4.9 | 0.6% | Feb 14, 2025 | Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the down... |
| CVE-2024-13735 | MEDIUM | 5.4 | 0.3% | Feb 14, 2025 | The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable ... |
| CVE-2024-9601 | MEDIUM | 5.4 | 0.3% | Feb 14, 2025 | The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’... |
| CVE-2024-57969 | MEDIUM | 4.3 | 0.2% | Feb 14, 2025 | app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search. |
| CVE-2024-7052 | MEDIUM | 4.8 | 0.3% | Feb 14, 2025 | The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-13692 | MEDIUM | 5.4 | 0.3% | Feb 14, 2025 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature... |
| CVE-2024-13493 | MEDIUM | 4.8 | 0.3% | Feb 14, 2025 | The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could a... |
| CVE-2024-10404 | MEDIUM | 4.4 | 0.1% | Feb 14, 2025 | CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could... |
| CVE-2024-57782 | MEDIUM | 6.8 | 0.2% | Feb 13, 2025 | An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service. |
| CVE-2024-56908 | MEDIUM | 6.8 | 0.6% | Feb 13, 2025 | In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file ... |
| CVE-2024-54951 | MEDIUM | 5.4 | 0.5% | Feb 13, 2025 | Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now