2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57913 | MEDIUM | 4.7 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Remove WARN_ON in functionfs_bin... |
| CVE-2024-8722 | MEDIUM | 5.5 | 0.3% | Jan 19, 2025 | The Import any XML or CSV File to WordPress PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV... |
| CVE-2024-45654 | MEDIUM | 4.3 | 0.3% | Jan 19, 2025 | IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted ... |
| CVE-2024-45653 | MEDIUM | 4.3 | 0.4% | Jan 19, 2025 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could disclose sensitive IP address information to authe... |
| CVE-2024-49824 | MEDIUM | 6.5 | 0.3% | Jan 18, 2025 | IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation ... |
| CVE-2024-51448 | MEDIUM | 6.7 | 0.1% | Jan 18, 2025 | IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate ... |
| CVE-2024-49338 | MEDIUM | 4.9 | 0.4% | Jan 18, 2025 | IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged u... |
| CVE-2024-13392 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-13519 | MEDIUM | 4.4 | 0.3% | Jan 18, 2025 | The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-13517 | MEDIUM | 4 | 0.2% | Jan 18, 2025 | The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Stored... |
| CVE-2024-13433 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' short... |
| CVE-2024-13432 | MEDIUM | 6.1 | 0.2% | Jan 18, 2025 | The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2024-13393 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2024-13391 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vuln... |
| CVE-2024-13385 | MEDIUM | 6.4 | 0.3% | Jan 18, 2025 | The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-13317 | MEDIUM | 4.3 | 0.2% | Jan 18, 2025 | The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2024-12696 | MEDIUM | 6.4 | 0.4% | Jan 18, 2025 | The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-12385 | MEDIUM | 6.1 | 0.2% | Jan 18, 2025 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-9020 | MEDIUM | 5.4 | 0.3% | Jan 18, 2025 | The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes bef... |
| CVE-2024-13516 | MEDIUM | 6.1 | 0.3% | Jan 18, 2025 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet... |
| CVE-2024-13515 | MEDIUM | 6.1 | 0.4% | Jan 18, 2025 | The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Si... |
| CVE-2024-12071 | MEDIUM | 5.3 | 0.4% | Jan 18, 2025 | The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerab... |
| CVE-2024-11923 | MEDIUM | 5.5 | 0.2% | Jan 18, 2025 | Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Fo... |
| CVE-2024-57252 | MEDIUM | 4.3 | 0.3% | Jan 17, 2025 | OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitr... |
| CVE-2024-57033 | MEDIUM | 6.1 | 0.3% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now