2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13401 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_pay... |
| CVE-2024-13398 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'checkout_for... |
| CVE-2024-51462 | MEDIUM | 5.3 | 0.4% | Jan 17, 2025 | IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter value... |
| CVE-2024-57785 | MEDIUM | 4.9 | 0.7% | Jan 16, 2025 | Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via the component amc_uplo... |
| CVE-2024-57784 | MEDIUM | 5.5 | 0.9% | Jan 16, 2025 | An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a direct... |
| CVE-2024-56144 | MEDIUM | 5.4 | 0.4% | Jan 16, 2025 | librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on t... |
| CVE-2024-40514 | MEDIUM | 4.6 | 0.3% | Jan 16, 2025 | Insecure Permissions vulnerability in themesebrand Chatvia v.5.3.2 allows a remote attacker to escalate privileges via t... |
| CVE-2024-40513 | MEDIUM | 4.6 | 0.4% | Jan 16, 2025 | An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload ... |
| CVE-2024-48460 | MEDIUM | 4.3 | 0.3% | Jan 16, 2025 | An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the S... |
| CVE-2024-57577 | MEDIUM | 5.7 | 0.3% | Jan 16, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan fu... |
| CVE-2024-56515 | MEDIUM | 6.5 | 0.6% | Jan 16, 2025 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnai... |
| CVE-2024-56136 | MEDIUM | 5.3 | 0.5% | Jan 16, 2025 | Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above ... |
| CVE-2024-52602 | MEDIUM | 5.3 | 0.6% | Jan 16, 2025 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) i... |
| CVE-2024-36402 | MEDIUM | 5.3 | 0.5% | Jan 16, 2025 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 ... |
| CVE-2024-57683 | MEDIUM | 4.3 | 0.5% | Jan 16, 2025 | An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenti... |
| CVE-2024-57682 | MEDIUM | 6.5 | 0.5% | Jan 16, 2025 | An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows u... |
| CVE-2024-57681 | MEDIUM | 5.3 | 0.5% | Jan 16, 2025 | An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated a... |
| CVE-2024-57680 | MEDIUM | 5.3 | 0.5% | Jan 16, 2025 | An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauth... |
| CVE-2024-57679 | MEDIUM | 6.5 | 0.6% | Jan 16, 2025 | An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthe... |
| CVE-2024-57678 | MEDIUM | 6.5 | 0.4% | Jan 16, 2025 | An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated ... |
| CVE-2024-57677 | MEDIUM | 6.5 | 0.6% | Jan 16, 2025 | An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated a... |
| CVE-2024-57676 | MEDIUM | 6.5 | 0.4% | Jan 16, 2025 | An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauth... |
| CVE-2024-52594 | MEDIUM | 4.3 | 0.3% | Jan 16, 2025 | Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery,... |
| CVE-2024-57776 | MEDIUM | 4.6 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allow... |
| CVE-2024-57774 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now