2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13878 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-13877 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before ou... |
| CVE-2024-13876 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13875 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2024-55009 | MEDIUM | 6.1 | 0.4% | Mar 19, 2025 | A reflected cross-site scripting (XSS) vulnerability in AutoBib - Bibliographic collection management system 3.1.140 and... |
| CVE-2024-7631 | MEDIUM | 4.3 | 0.5% | Mar 19, 2025 | A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/re... |
| CVE-2024-57061 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via ... |
| CVE-2024-51459 | HIGH | 7.8 | 0.1% | Mar 19, 2025 | IBM InfoSphere Information Server 11.7 could allow a local user to execute privileged commands due to the improper handl... |
| CVE-2024-25132 | MEDIUM | 4.3 | 0.3% | Mar 19, 2025 | A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshi... |
| CVE-2024-53970 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-53969 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-53968 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-53967 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-42176 | HIGH | 8 | 0.2% | Mar 19, 2025 | HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous ... |
| CVE-2024-55551 | HIGH | 8.3 | 0.6% | Mar 19, 2025 | An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into... |
| CVE-2024-45644 | MEDIUM | 4.7 | 0.3% | Mar 19, 2025 | IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatical... |
| CVE-2024-13933 | HIGH | 8.8 | 0.2% | Mar 19, 2025 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request F... |
| CVE-2024-13442 | CRITICAL | 9.8 | 0.4% | Mar 19, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2024-12920 | HIGH | 8.8 | 0.4% | Mar 19, 2025 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access ... |
| CVE-2024-13790 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion ... |
| CVE-2024-12137 | HIGH | 7.6 | 0.2% | Mar 19, 2025 | Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking. T... |
| CVE-2024-12136 | HIGH | 7.8 | 0.1% | Mar 19, 2025 | Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass... |
| CVE-2024-13412 | HIGH | 7.5 | 0.3% | Mar 19, 2025 | The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2024-13410 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ... |
| CVE-2024-50631 | HIGH | 7.5 | 24.9% | Mar 19, 2025 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now