2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12436 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attacker... |
| CVE-2024-12280 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which coul... |
| CVE-2024-28771 | MEDIUM | 6.5 | 0.2% | Jan 27, 2025 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr... |
| CVE-2024-28770 | MEDIUM | 6.5 | 0.2% | Jan 27, 2025 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr... |
| CVE-2024-31906 | MEDIUM | 6.2 | 0.2% | Jan 26, 2025 | IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the s... |
| CVE-2024-13505 | MEDIUM | 4.8 | 0.2% | Jan 26, 2025 | The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8... |
| CVE-2024-12334 | MEDIUM | 6.1 | 0.3% | Jan 26, 2025 | The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Sc... |
| CVE-2024-10636 | MEDIUM | 6.1 | 0.3% | Jan 26, 2025 | The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via... |
| CVE-2024-35150 | MEDIUM | 5.3 | 0.3% | Jan 25, 2025 | IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is wr... |
| CVE-2024-35145 | MEDIUM | 6.1 | 0.2% | Jan 25, 2025 | IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2024-35144 | MEDIUM | 5.3 | 0.3% | Jan 25, 2025 | IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid... |
| CVE-2024-35134 | MEDIUM | 5.3 | 0.4% | Jan 25, 2025 | IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical er... |
| CVE-2024-35114 | MEDIUM | 5.3 | 0.4% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discr... |
| CVE-2024-35113 | MEDIUM | 6.5 | 0.3% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through... |
| CVE-2024-35112 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed techn... |
| CVE-2024-35111 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technic... |
| CVE-2024-13450 | MEDIUM | 6.5 | 0.4% | Jan 25, 2025 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
| CVE-2024-13449 | MEDIUM | 4.3 | 0.3% | Jan 25, 2025 | The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2024-13599 | MEDIUM | 5.4 | 0.3% | Jan 25, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions ... |
| CVE-2024-13586 | MEDIUM | 5.4 | 0.2% | Jan 25, 2025 | The Masy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'justified-gallery' ... |
| CVE-2024-13551 | MEDIUM | 5.4 | 0.3% | Jan 25, 2025 | The ABC Notation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abcjs' shortcode in... |
| CVE-2024-13550 | MEDIUM | 6.5 | 0.6% | Jan 25, 2025 | The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via th... |
| CVE-2024-13548 | MEDIUM | 5.4 | 0.3% | Jan 25, 2025 | The Power Ups for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'magic-bu... |
| CVE-2024-13467 | MEDIUM | 6.1 | 0.3% | Jan 25, 2025 | The WP Contact Form7 Email Spam Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'po... |
| CVE-2024-13458 | MEDIUM | 5.4 | 0.2% | Jan 25, 2025 | The WordPress SEO Friendly Accordion FAQ with AI assisted content generation plugin for WordPress is vulnerable to Store... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now