2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48818 | CRITICAL | 9.8 | 0.8% | Mar 25, 2025 | An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code. |
| CVE-2024-31896 | HIGH | 7.5 | 0.2% | Mar 25, 2025 | IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow... |
| CVE-2024-58105 | HIGH | 7.8 | 0.2% | Mar 25, 2025 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ... |
| CVE-2024-58104 | HIGH | 7.8 | 0.2% | Mar 25, 2025 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ... |
| CVE-2024-55604 | MEDIUM | 4.3 | 0.2% | Mar 25, 2025 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not h... |
| CVE-2024-42533 | CRITICAL | 9.8 | 0.6% | Mar 25, 2025 | SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attacker... |
| CVE-2024-12169 | HIGH | 8.7 | 0.4% | Mar 25, 2025 | A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allo... |
| CVE-2024-11499 | MEDIUM | 6.9 | 0.2% | Mar 25, 2025 | A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and auth... |
| CVE-2024-10037 | MEDIUM | 5.9 | 0.3% | Mar 25, 2025 | A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU applicati... |
| CVE-2024-53679 | MEDIUM | 5.4 | 0.5% | Mar 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the ... |
| CVE-2024-53678 | HIGH | 8.8 | 0.6% | Mar 25, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users ... |
| CVE-2024-13731 | MEDIUM | 6.4 | 0.3% | Mar 25, 2025 | The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-13710 | MEDIUM | 4.3 | 0.1% | Mar 25, 2025 | The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2024-13690 | HIGH | 7.2 | 0.3% | Mar 25, 2025 | The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submi... |
| CVE-2024-12623 | MEDIUM | 6.4 | 0.3% | Mar 25, 2025 | The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in ... |
| CVE-2024-9770 | MEDIUM | 4.7 | 0.3% | Mar 25, 2025 | The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statem... |
| CVE-2024-44903 | HIGH | 7.5 | 0.3% | Mar 25, 2025 | SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is ava... |
| CVE-2024-13863 | HIGH | 7.1 | 0.3% | Mar 25, 2025 | The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputt... |
| CVE-2024-13618 | HIGH | 7.2 | 0.3% | Mar 25, 2025 | The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.... |
| CVE-2024-13617 | HIGH | 8.6 | 0.4% | Mar 25, 2025 | The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unau... |
| CVE-2024-13123 | LOW | 3.5 | 0.2% | Mar 25, 2025 | The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi... |
| CVE-2024-13122 | LOW | 3.5 | 0.2% | Mar 25, 2025 | The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privi... |
| CVE-2024-13118 | MEDIUM | 4.3 | 0.2% | Mar 25, 2025 | The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers t... |
| CVE-2024-12769 | LOW | 3.5 | 0.2% | Mar 25, 2025 | The Simple Banner WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2024-12682 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now