2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56197 | MEDIUM | 4.9 | 0.3% | Feb 4, 2025 | Discourse is an open source platform for community discussion. PM titles and metadata can be read by other users when th... |
| CVE-2024-45658 | MEDIUM | 5.3 | 0.4% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensiti... |
| CVE-2024-45657 | MEDIUM | 6.7 | 0.1% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a local privileged user to perform ... |
| CVE-2024-40700 | MEDIUM | 6.1 | 0.3% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site scripting. This vul... |
| CVE-2024-35138 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 is vulnerable to cross-site request forgery whi... |
| CVE-2024-48019 | MEDIUM | 5.4 | 0.9% | Feb 4, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to Exter... |
| CVE-2024-45659 | MEDIUM | 5.3 | 0.3% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensiti... |
| CVE-2024-11623 | MEDIUM | 4.8 | 0.3% | Feb 4, 2025 | Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application i... |
| CVE-2024-13699 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter... |
| CVE-2024-27137 | MEDIUM | 5.3 | 0.3% | Feb 4, 2025 | In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration... |
| CVE-2024-13733 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-13529 | MEDIUM | 6.5 | 0.4% | Feb 4, 2025 | The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of ... |
| CVE-2024-13510 | MEDIUM | 6.1 | 0.1% | Feb 4, 2025 | The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.... |
| CVE-2024-13356 | MEDIUM | 6.5 | 0.2% | Feb 4, 2025 | The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2024-13403 | MEDIUM | 5.4 | 0.4% | Feb 4, 2025 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu... |
| CVE-2024-13514 | MEDIUM | 4.3 | 0.3% | Feb 4, 2025 | The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions u... |
| CVE-2024-12046 | MEDIUM | 4.3 | 0.4% | Feb 4, 2025 | The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u... |
| CVE-2024-13607 | MEDIUM | 4.3 | 0.4% | Feb 4, 2025 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object ... |
| CVE-2024-12597 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'b... |
| CVE-2024-13332 | MEDIUM | 6.1 | 0.3% | Feb 4, 2025 | The TransFinanz WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2024-13331 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back... |
| CVE-2024-13328 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2024-13327 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13326 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2024-13325 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now