2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13115 | MEDIUM | 6.1 | 0.2% | Feb 4, 2025 | The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places,... |
| CVE-2024-13114 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter... |
| CVE-2024-44449 | MEDIUM | 6.1 | 0.5% | Feb 3, 2025 | Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive informat... |
| CVE-2024-57498 | MEDIUM | 4.8 | 0.3% | Feb 3, 2025 | Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the... |
| CVE-2024-57097 | MEDIUM | 4.8 | 0.2% | Feb 3, 2025 | ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php. |
| CVE-2024-56946 | MEDIUM | 5.3 | 0.4% | Feb 3, 2025 | Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the s... |
| CVE-2024-11134 | MEDIUM | 6.5 | 0.3% | Feb 3, 2025 | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '... |
| CVE-2024-11133 | MEDIUM | 5.3 | 0.3% | Feb 3, 2025 | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '... |
| CVE-2024-11132 | MEDIUM | 5.4 | 0.2% | Feb 3, 2025 | The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and incl... |
| CVE-2024-57237 | MEDIUM | 6.3 | 0.3% | Feb 3, 2025 | Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endp... |
| CVE-2024-57004 | MEDIUM | 6.1 | 27.8% | Feb 3, 2025 | Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malici... |
| CVE-2024-50656 | MEDIUM | 6.1 | 0.3% | Feb 3, 2025 | itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi... |
| CVE-2024-12510 | MEDIUM | 6.7 | 0.9% | Feb 3, 2025 | If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. T... |
| CVE-2024-57967 | MEDIUM | 4.2 | 0.2% | Feb 3, 2025 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated ... |
| CVE-2024-57175 | MEDIUM | 5.4 | 0.3% | Feb 3, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 ... |
| CVE-2024-54840 | MEDIUM | 6.1 | 0.1% | Feb 3, 2025 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address... |
| CVE-2024-53943 | MEDIUM | 6.1 | 0.3% | Feb 3, 2025 | An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln... |
| CVE-2024-53942 | MEDIUM | 4.8 | 15.2% | Feb 3, 2025 | An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln... |
| CVE-2024-36437 | MEDIUM | 6.5 | 0.2% | Feb 3, 2025 | The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any insta... |
| CVE-2024-55456 | MEDIUM | 6.5 | 0.4% | Feb 3, 2025 | lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell |
| CVE-2024-38417 | MEDIUM | 5.5 | 0.1% | Feb 3, 2025 | Information disclosure while processing IO control commands. |
| CVE-2024-38416 | MEDIUM | 5.5 | 0.1% | Feb 3, 2025 | Information disclosure during audio playback. |
| CVE-2024-38414 | MEDIUM | 5.5 | 0.1% | Feb 3, 2025 | Information disclosure while processing information on firmware image during core initialization. |
| CVE-2024-57522 | MEDIUM | 6.4 | 0.9% | Feb 3, 2025 | SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An at... |
| CVE-2024-6790 | MEDIUM | 6.1 | 0.1% | Feb 3, 2025 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valha... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now