2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12385 | MEDIUM | 6.1 | 0.2% | Jan 18, 2025 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-9020 | MEDIUM | 5.4 | 0.3% | Jan 18, 2025 | The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes bef... |
| CVE-2024-13516 | MEDIUM | 6.1 | 0.3% | Jan 18, 2025 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet... |
| CVE-2024-13515 | MEDIUM | 6.1 | 0.4% | Jan 18, 2025 | The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Si... |
| CVE-2024-12071 | MEDIUM | 5.3 | 0.4% | Jan 18, 2025 | The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerab... |
| CVE-2024-11923 | MEDIUM | 5.5 | 0.2% | Jan 18, 2025 | Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Fo... |
| CVE-2024-57252 | MEDIUM | 4.3 | 0.3% | Jan 17, 2025 | OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitr... |
| CVE-2024-57033 | MEDIUM | 6.1 | 0.3% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php. |
| CVE-2024-57372 | MEDIUM | 6.1 | 0.4% | Jan 17, 2025 | Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive inform... |
| CVE-2024-57370 | MEDIUM | 6.1 | 0.4% | Jan 17, 2025 | Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain se... |
| CVE-2024-57369 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | Clickjacking vulnerability in typecho v1.2.1. |
| CVE-2024-13026 | MEDIUM | 6.1 | 0.1% | Jan 17, 2025 | A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The ... |
| CVE-2024-53683 | MEDIUM | 5.6 | 0.2% | Jan 17, 2025 | A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An... |
| CVE-2024-45832 | MEDIUM | 4.3 | 0.3% | Jan 17, 2025 | Hard-coded credentials were included as part of the application binary. These credentials served as part of the applica... |
| CVE-2024-26157 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-26156 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-26154 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-50967 | MEDIUM | 6.5 | 1.6% | Jan 17, 2025 | The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability.... |
| CVE-2024-10498 | MEDIUM | 6.9 | 0.4% | Jan 17, 2025 | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow a... |
| CVE-2024-13378 | MEDIUM | 5.4 | 0.3% | Jan 17, 2025 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter i... |
| CVE-2024-12370 | MEDIUM | 5.3 | 0.3% | Jan 17, 2025 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2024-11139 | MEDIUM | 4.6 | 0.2% | Jan 17, 2025 | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow l... |
| CVE-2024-13386 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all ... |
| CVE-2024-13367 | MEDIUM | 6.5 | 0.4% | Jan 17, 2025 | The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_do... |
| CVE-2024-13366 | MEDIUM | 6.1 | 0.3% | Jan 17, 2025 | The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now