2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23962 | MEDIUM | 5.3 | 0.7% | Jan 31, 2025 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 d... |
| CVE-2024-23937 | MEDIUM | 4.3 | 0.4% | Jan 31, 2025 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sili... |
| CVE-2024-23930 | MEDIUM | 4.3 | 0.5% | Jan 31, 2025 | This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations o... |
| CVE-2024-23928 | MEDIUM | 6.5 | 0.2% | Jan 31, 2025 | This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected i... |
| CVE-2024-10604 | MEDIUM | 5.3 | 0.2% | Jan 30, 2025 | Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, ... |
| CVE-2024-10603 | MEDIUM | 5.3 | 0.3% | Jan 30, 2025 | Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be ... |
| CVE-2024-10026 | MEDIUM | 5.3 | 0.2% | Jan 30, 2025 | A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate ... |
| CVE-2024-55417 | MEDIUM | 4.3 | 12.3% | Jan 30, 2025 | DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user u... |
| CVE-2024-55415 | MEDIUM | 5.7 | 14.6% | Jan 30, 2025 | DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass. |
| CVE-2024-53615 | MEDIUM | 6.5 | 1.3% | Jan 30, 2025 | A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through... |
| CVE-2024-8494 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u... |
| CVE-2024-13715 | MEDIUM | 4.3 | 0.2% | Jan 30, 2025 | The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability che... |
| CVE-2024-13705 | MEDIUM | 6.1 | 0.3% | Jan 30, 2025 | The StageShow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg wi... |
| CVE-2024-13700 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortco... |
| CVE-2024-13670 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The Music Sheet Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pn_msv' short... |
| CVE-2024-13664 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The WP Post List Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpb_post_list... |
| CVE-2024-13661 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | The Table Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wptableeditor_vtabs... |
| CVE-2024-13652 | MEDIUM | 4.3 | 0.3% | Jan 30, 2025 | The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing cap... |
| CVE-2024-13596 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Injec... |
| CVE-2024-13549 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in... |
| CVE-2024-13512 | MEDIUM | 5.4 | 0.1% | Jan 30, 2025 | The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-13460 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The WE – Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Testimonial Author Nam... |
| CVE-2024-13400 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gu... |
| CVE-2024-13349 | MEDIUM | 5.4 | 0.3% | Jan 30, 2025 | The Stockdio Historical Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stockd... |
| CVE-2024-12861 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now