2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10210 | HIGH | 8.4 | 0.4% | Mar 25, 2025 | An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an ... |
| CVE-2024-10105 | MEDIUM | 5.9 | 0.3% | Mar 25, 2025 | The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-8315 | MEDIUM | 6.8 | 0.1% | Mar 25, 2025 | An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may ... |
| CVE-2024-8314 | MEDIUM | 5.5 | 0.3% | Mar 25, 2025 | An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in ... |
| CVE-2024-8313 | HIGH | 8.7 | 0.2% | Mar 25, 2025 | An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an I... |
| CVE-2024-45484 | HIGH | 7.2 | 0.2% | Mar 25, 2025 | An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used... |
| CVE-2024-45483 | HIGH | 7 | 0.2% | Mar 25, 2025 | A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow ... |
| CVE-2024-45482 | HIGH | 8.5 | 0.1% | Mar 25, 2025 | An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may a... |
| CVE-2024-45481 | HIGH | 8.5 | 0.1% | Mar 25, 2025 | An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may all... |
| CVE-2024-45480 | CRITICAL | 9.2 | 0.4% | Mar 25, 2025 | An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APR... |
| CVE-2024-10209 | HIGH | 8.5 | 0.1% | Mar 25, 2025 | An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may ... |
| CVE-2024-10208 | MEDIUM | 5.1 | 0.4% | Mar 25, 2025 | An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <... |
| CVE-2024-10207 | MEDIUM | 5.3 | 0.3% | Mar 25, 2025 | A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticat... |
| CVE-2024-10206 | MEDIUM | 6.9 | 0.4% | Mar 25, 2025 | A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthentic... |
| CVE-2024-9103 | MEDIUM | 6.1 | 0.2% | Mar 24, 2025 | Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messag... |
| CVE-2024-55279 | MEDIUM | 6 | 0.3% | Mar 24, 2025 | Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files. |
| CVE-2024-8774 | HIGH | 7.7 | 0.3% | Mar 24, 2025 | The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to e... |
| CVE-2024-8773 | HIGH | 8.3 | 0.4% | Mar 24, 2025 | SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt... |
| CVE-2024-13124 | LOW | 3.5 | 0.2% | Mar 24, 2025 | The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-10558 | LOW | 3.5 | 0.2% | Mar 24, 2025 | The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-13666 | MEDIUM | 5.3 | 0.3% | Mar 22, 2025 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2024-13856 | MEDIUM | 6.4 | 0.3% | Mar 22, 2025 | The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Fo... |
| CVE-2024-13768 | MEDIUM | 4.3 | 0.1% | Mar 22, 2025 | The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-S... |
| CVE-2024-13739 | MEDIUM | 6.1 | 0.2% | Mar 22, 2025 | The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versi... |
| CVE-2024-13737 | MEDIUM | 4.3 | 0.3% | Mar 22, 2025 | The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data d... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now