2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12620 | MEDIUM | 5.3 | 0.3% | Feb 1, 2025 | The AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations plugin for WordPress is vulnerable to u... |
| CVE-2024-12184 | MEDIUM | 5.3 | 0.4% | Feb 1, 2025 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missin... |
| CVE-2024-11780 | MEDIUM | 5.4 | 0.2% | Feb 1, 2025 | The Site Search 360 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ss360-resultbloc... |
| CVE-2024-57435 | MEDIUM | 6.5 | 0.4% | Jan 31, 2025 | In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a nul... |
| CVE-2024-53354 | MEDIUM | 6.5 | 0.5% | Jan 31, 2025 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated at... |
| CVE-2024-49349 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored ... |
| CVE-2024-49339 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.1 is vulnerable to stored ... |
| CVE-2024-42671 | MEDIUM | 6.1 | 0.3% | Jan 31, 2025 | A Host Header Poisoning Open Redirect issue in slabiak Appointment Scheduler v.1.0.5 allows a remote attacker to redirec... |
| CVE-2024-49807 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored... |
| CVE-2024-47116 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-... |
| CVE-2024-47103 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-... |
| CVE-2024-45089 | MEDIUM | 4.3 | 0.3% | Jan 31, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allo... |
| CVE-2024-40696 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-... |
| CVE-2024-11741 | MEDIUM | 4.3 | 0.4% | Jan 31, 2025 | Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not... |
| CVE-2024-57948 | MEDIUM | 5.5 | 0.2% | Jan 31, 2025 | In the Linux kernel, the following vulnerability has been resolved: mac802154: check local interfaces before deleting s... |
| CVE-2024-13662 | MEDIUM | 6.4 | 0.3% | Jan 31, 2025 | The eHive Objects Image Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ehive_o... |
| CVE-2024-12415 | MEDIUM | 6.5 | 0.4% | Jan 31, 2025 | The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, ... |
| CVE-2024-12037 | MEDIUM | 6.4 | 0.2% | Jan 31, 2025 | The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p... |
| CVE-2024-44055 | MEDIUM | 5.4 | 0.2% | Jan 31, 2025 | Server-Side Request Forgery (SSRF) vulnerability in brandexponents Oshine Modules oshine-modules.This issue affects Oshi... |
| CVE-2024-13566 | MEDIUM | 6.4 | 0.4% | Jan 31, 2025 | The WP DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all version... |
| CVE-2024-13157 | MEDIUM | 6.4 | 0.4% | Jan 31, 2025 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2024-53007 | MEDIUM | 6.4 | 0.1% | Jan 31, 2025 | Bentley Systems ProjectWise Integration Server before 10.00.03.288 allows unintended SQL query execution by an authentic... |
| CVE-2024-13530 | MEDIUM | 4.3 | 0.3% | Jan 31, 2025 | The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login ... |
| CVE-2024-13623 | MEDIUM | 5.9 | 0.4% | Jan 31, 2025 | The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2024-13717 | MEDIUM | 4.3 | 0.2% | Jan 31, 2025 | The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data du... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now