2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57372 | MEDIUM | 6.1 | 0.4% | Jan 17, 2025 | Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive inform... |
| CVE-2024-57370 | MEDIUM | 6.1 | 0.4% | Jan 17, 2025 | Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain se... |
| CVE-2024-57369 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | Clickjacking vulnerability in typecho v1.2.1. |
| CVE-2024-13026 | MEDIUM | 6.1 | 0.1% | Jan 17, 2025 | A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The ... |
| CVE-2024-53683 | MEDIUM | 5.6 | 0.2% | Jan 17, 2025 | A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An... |
| CVE-2024-45832 | MEDIUM | 4.3 | 0.3% | Jan 17, 2025 | Hard-coded credentials were included as part of the application binary. These credentials served as part of the applica... |
| CVE-2024-26157 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-26156 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-26154 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-50967 | MEDIUM | 6.5 | 1.6% | Jan 17, 2025 | The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability.... |
| CVE-2024-10498 | MEDIUM | 6.9 | 0.4% | Jan 17, 2025 | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow a... |
| CVE-2024-13378 | MEDIUM | 5.4 | 0.3% | Jan 17, 2025 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter i... |
| CVE-2024-12370 | MEDIUM | 5.3 | 0.3% | Jan 17, 2025 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2024-11139 | MEDIUM | 4.6 | 0.2% | Jan 17, 2025 | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow l... |
| CVE-2024-13386 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all ... |
| CVE-2024-13367 | MEDIUM | 6.5 | 0.4% | Jan 17, 2025 | The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_do... |
| CVE-2024-13366 | MEDIUM | 6.1 | 0.3% | Jan 17, 2025 | The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versio... |
| CVE-2024-12637 | MEDIUM | 5.3 | 0.5% | Jan 17, 2025 | The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2024-12598 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ p... |
| CVE-2024-12508 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'g... |
| CVE-2024-12466 | MEDIUM | 6.1 | 0.4% | Jan 17, 2025 | The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all v... |
| CVE-2024-12203 | MEDIUM | 4.4 | 0.3% | Jan 17, 2025 | The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_color’ parameter in ... |
| CVE-2024-11146 | MEDIUM | 6.3 | 0.3% | Jan 17, 2025 | TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-... |
| CVE-2024-10799 | MEDIUM | 6.5 | 0.7% | Jan 17, 2025 | The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via th... |
| CVE-2024-13434 | MEDIUM | 6.1 | 0.3% | Jan 17, 2025 | The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramete... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now