2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11348 | MEDIUM | 5.3 | 0.4% | Jan 27, 2025 | Eura7 CMSmanager in version 4.6 and below is vulnerable to Reflected XSS attacks through manipulation of return GET requ... |
| CVE-2024-55931 | MEDIUM | 6.5 | 0.3% | Jan 27, 2025 | Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is... |
| CVE-2024-12345 | MEDIUM | 6.7 | 0.2% | Jan 27, 2025 | A vulnerability classified as problematic was found in INW Krbyyyzo 25.2002. Affected by this vulnerability is an unknow... |
| CVE-2024-52012 | MEDIUM | 5.4 | 43.3% | Jan 27, 2025 | Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary fil... |
| CVE-2024-43445 | MEDIUM | 5.4 | 0.2% | Jan 27, 2025 | A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-O... |
| CVE-2024-13117 | MEDIUM | 6.5 | 0.5% | Jan 27, 2025 | The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and ... |
| CVE-2024-13095 | MEDIUM | 4.8 | 0.3% | Jan 27, 2025 | The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL st... |
| CVE-2024-12774 | MEDIUM | 6.5 | 0.2% | Jan 27, 2025 | The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers t... |
| CVE-2024-12436 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attacker... |
| CVE-2024-12280 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which coul... |
| CVE-2024-28771 | MEDIUM | 6.5 | 0.2% | Jan 27, 2025 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr... |
| CVE-2024-28770 | MEDIUM | 6.5 | 0.2% | Jan 27, 2025 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr... |
| CVE-2024-31906 | MEDIUM | 6.2 | 0.2% | Jan 26, 2025 | IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the s... |
| CVE-2024-13505 | MEDIUM | 4.8 | 0.2% | Jan 26, 2025 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8... |
| CVE-2024-12334 | MEDIUM | 6.1 | 0.3% | Jan 26, 2025 | The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Sc... |
| CVE-2024-10636 | MEDIUM | 6.1 | 0.3% | Jan 26, 2025 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via... |
| CVE-2024-35150 | MEDIUM | 5.3 | 0.3% | Jan 25, 2025 | IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is wr... |
| CVE-2024-35145 | MEDIUM | 6.1 | 0.2% | Jan 25, 2025 | IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2024-35144 | MEDIUM | 5.3 | 0.3% | Jan 25, 2025 | IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid... |
| CVE-2024-35134 | MEDIUM | 5.3 | 0.4% | Jan 25, 2025 | IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical er... |
| CVE-2024-35114 | MEDIUM | 5.3 | 0.4% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discr... |
| CVE-2024-35113 | MEDIUM | 6.5 | 0.3% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through... |
| CVE-2024-35112 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed techn... |
| CVE-2024-35111 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technic... |
| CVE-2024-13450 | MEDIUM | 6.5 | 0.4% | Jan 25, 2025 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now