2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11913 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all... |
| CVE-2024-10324 | MEDIUM | 4.3 | 0.3% | Jan 24, 2025 | The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t... |
| CVE-2024-13594 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofi... |
| CVE-2024-13572 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | The Precious Metals Charts and Widgets for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-13542 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Store... |
| CVE-2024-13354 | MEDIUM | 5.4 | 0.2% | Jan 24, 2025 | The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne... |
| CVE-2024-13335 | MEDIUM | 4.3 | 0.2% | Jan 24, 2025 | The Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templates plugin for WordPress is vulnerable to unau... |
| CVE-2024-13583 | MEDIUM | 5.4 | 0.3% | Jan 24, 2025 | The Simple Gallery with Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c2tw_... |
| CVE-2024-12494 | MEDIUM | 5.4 | 0.3% | Jan 24, 2025 | The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_ma... |
| CVE-2024-13683 | MEDIUM | 4.3 | 0.2% | Jan 24, 2025 | The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2024-13680 | MEDIUM | 6.5 | 0.4% | Jan 24, 2025 | The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL... |
| CVE-2024-13659 | MEDIUM | 5.4 | 0.3% | Jan 24, 2025 | The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortco... |
| CVE-2024-11931 | MEDIUM | 5.3 | 0.3% | Jan 24, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior ... |
| CVE-2024-57556 | MEDIUM | 6.1 | 0.3% | Jan 23, 2025 | Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary cod... |
| CVE-2024-57386 | MEDIUM | 6.1 | 0.4% | Jan 23, 2025 | Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile... |
| CVE-2024-57329 | MEDIUM | 5.4 | 0.3% | Jan 23, 2025 | HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize o... |
| CVE-2024-57326 | MEDIUM | 6.1 | 0.3% | Jan 23, 2025 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1... |
| CVE-2024-50665 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box. |
| CVE-2024-55929 | MEDIUM | 5.3 | 0.2% | Jan 23, 2025 | A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as thou... |
| CVE-2024-45672 | MEDIUM | 6 | 0.1% | Jan 23, 2025 | IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive ... |
| CVE-2024-52327 | MEDIUM | 6.5 | 0.5% | Jan 23, 2025 | The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry re... |
| CVE-2024-12079 | MEDIUM | 4.8 | 0.1% | Jan 23, 2025 | ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmow... |
| CVE-2024-12078 | MEDIUM | 6.3 | 0.3% | Jan 23, 2025 | ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated a... |
| CVE-2024-10846 | MEDIUM | 5.9 | 0.2% | Jan 23, 2025 | The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to... |
| CVE-2024-57947 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now