2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45351 | HIGH | 7.8 | 0.2% | Mar 26, 2025 | A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by imp... |
| CVE-2024-13889 | HIGH | 7.2 | 0.7% | Mar 26, 2025 | The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ... |
| CVE-2024-13411 | MEDIUM | 6.4 | 0.3% | Mar 26, 2025 | The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in... |
| CVE-2024-13801 | HIGH | 8.1 | 0.3% | Mar 26, 2025 | The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a ... |
| CVE-2024-13702 | MEDIUM | 5.4 | 0.2% | Mar 26, 2025 | The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-30155 | MEDIUM | 4.3 | 0.2% | Mar 26, 2025 | HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able t... |
| CVE-2024-13146 | HIGH | 8.8 | 0.2% | Mar 26, 2025 | The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow att... |
| CVE-2024-12683 | LOW | 3.5 | 0.2% | Mar 26, 2025 | The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-11847 | MEDIUM | 4.8 | 0.2% | Mar 26, 2025 | The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least ... |
| CVE-2024-47516 | CRITICAL | 9.8 | 0.8% | Mar 26, 2025 | A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to re... |
| CVE-2024-55030 | CRITICAL | 9.8 | 1.7% | Mar 25, 2025 | A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute ar... |
| CVE-2024-55029 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. |
| CVE-2024-55028 | CRITICAL | 9.8 | 0.7% | Mar 25, 2025 | A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via... |
| CVE-2024-48818 | CRITICAL | 9.8 | 0.8% | Mar 25, 2025 | An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code. |
| CVE-2024-31896 | HIGH | 7.5 | 0.2% | Mar 25, 2025 | IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow... |
| CVE-2024-58105 | HIGH | 7.8 | 0.2% | Mar 25, 2025 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ... |
| CVE-2024-58104 | HIGH | 7.8 | 0.2% | Mar 25, 2025 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ... |
| CVE-2024-55604 | MEDIUM | 4.3 | 0.2% | Mar 25, 2025 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not h... |
| CVE-2024-42533 | CRITICAL | 9.8 | 0.6% | Mar 25, 2025 | SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attacker... |
| CVE-2024-12169 | HIGH | 8.7 | 0.4% | Mar 25, 2025 | A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allo... |
| CVE-2024-11499 | MEDIUM | 6.9 | 0.2% | Mar 25, 2025 | A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and auth... |
| CVE-2024-10037 | MEDIUM | 5.9 | 0.3% | Mar 25, 2025 | A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU applicati... |
| CVE-2024-53679 | MEDIUM | 5.4 | 0.5% | Mar 25, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the ... |
| CVE-2024-53678 | HIGH | 8.8 | 0.6% | Mar 25, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users ... |
| CVE-2024-13731 | MEDIUM | 6.4 | 0.3% | Mar 25, 2025 | The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now