2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10206 | MEDIUM | 6.9 | 0.4% | Mar 25, 2025 | A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthentic... |
| CVE-2024-9103 | MEDIUM | 6.1 | 0.2% | Mar 24, 2025 | Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messag... |
| CVE-2024-55279 | MEDIUM | 6 | 0.3% | Mar 24, 2025 | Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files. |
| CVE-2024-8774 | HIGH | 7.7 | 0.3% | Mar 24, 2025 | The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to e... |
| CVE-2024-8773 | HIGH | 8.3 | 0.4% | Mar 24, 2025 | SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt... |
| CVE-2024-13124 | LOW | 3.5 | 0.2% | Mar 24, 2025 | The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-10558 | LOW | 3.5 | 0.2% | Mar 24, 2025 | The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-13666 | MEDIUM | 5.3 | 0.3% | Mar 22, 2025 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2024-13856 | MEDIUM | 6.4 | 0.3% | Mar 22, 2025 | The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Fo... |
| CVE-2024-13768 | MEDIUM | 4.3 | 0.1% | Mar 22, 2025 | The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-S... |
| CVE-2024-13739 | MEDIUM | 6.1 | 0.2% | Mar 22, 2025 | The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versi... |
| CVE-2024-13737 | MEDIUM | 4.3 | 0.3% | Mar 22, 2025 | The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2024-53351 | CRITICAL | 9.8 | 0.5% | Mar 21, 2025 | Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalatio... |
| CVE-2024-53350 | HIGH | 7.4 | 0.4% | Mar 21, 2025 | Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escal... |
| CVE-2024-53349 | HIGH | 7.4 | 0.4% | Mar 21, 2025 | Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escal... |
| CVE-2024-53348 | HIGH | 7.4 | 0.3% | Mar 21, 2025 | LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive informati... |
| CVE-2024-57490 | HIGH | 7.7 | 0.4% | Mar 21, 2025 | Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system ... |
| CVE-2024-13903 | HIGH | 7.5 | 0.7% | Mar 21, 2025 | A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulne... |
| CVE-2024-50053 | MEDIUM | 5.4 | 1.0% | Mar 21, 2025 | Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below... |
| CVE-2024-54564 | MEDIUM | 6.5 | 0.3% | Mar 21, 2025 | This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonom... |
| CVE-2024-54551 | HIGH | 7.5 | 0.6% | Mar 21, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, mac... |
| CVE-2024-44305 | HIGH | 7.8 | 0.1% | Mar 21, 2025 | This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able t... |
| CVE-2024-44199 | HIGH | 7.1 | 0.2% | Mar 21, 2025 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may... |
| CVE-2024-7598 | LOW | 3.1 | 0.3% | Mar 20, 2025 | A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enf... |
| CVE-2024-57440 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webpr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now