2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57680 | MEDIUM | 5.3 | 0.5% | Jan 16, 2025 | An access control issue in the component form2PortriggerRule.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauth... |
| CVE-2024-57679 | MEDIUM | 6.5 | 0.6% | Jan 16, 2025 | An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthe... |
| CVE-2024-57678 | MEDIUM | 6.5 | 0.4% | Jan 16, 2025 | An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated ... |
| CVE-2024-57677 | MEDIUM | 6.5 | 0.6% | Jan 16, 2025 | An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated a... |
| CVE-2024-57676 | MEDIUM | 6.5 | 0.4% | Jan 16, 2025 | An access control issue in the component form2WlanBasicSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauth... |
| CVE-2024-52594 | MEDIUM | 4.3 | 0.3% | Jan 16, 2025 | Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery,... |
| CVE-2024-57776 | MEDIUM | 4.6 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allow... |
| CVE-2024-57774 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.... |
| CVE-2024-57773 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 ... |
| CVE-2024-57772 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 ... |
| CVE-2024-57771 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allow... |
| CVE-2024-41746 | MEDIUM | 6.1 | 0.2% | Jan 16, 2025 | IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allo... |
| CVE-2024-57161 | MEDIUM | 4.3 | 0.2% | Jan 16, 2025 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit... |
| CVE-2024-57160 | MEDIUM | 4.3 | 0.2% | Jan 16, 2025 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html. |
| CVE-2024-13387 | MEDIUM | 6.4 | 0.3% | Jan 16, 2025 | The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shor... |
| CVE-2024-13355 | MEDIUM | 5.4 | 0.4% | Jan 16, 2025 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited fi... |
| CVE-2024-12615 | MEDIUM | 6.5 | 0.5% | Jan 16, 2025 | The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX ac... |
| CVE-2024-12614 | MEDIUM | 4.3 | 0.4% | Jan 16, 2025 | The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-12427 | MEDIUM | 5.3 | 0.4% | Jan 16, 2025 | The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability c... |
| CVE-2024-12226 | MEDIUM | 6.5 | 0.3% | Jan 16, 2025 | In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes s... |
| CVE-2024-11452 | MEDIUM | 6.4 | 0.3% | Jan 16, 2025 | The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-10789 | MEDIUM | 4.3 | 0.2% | Jan 16, 2025 | The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-10970 | MEDIUM | 5.4 | 0.3% | Jan 16, 2025 | The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution i... |
| CVE-2024-41454 | MEDIUM | 6.5 | 0.5% | Jan 15, 2025 | An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-... |
| CVE-2024-41453 | MEDIUM | 4.8 | 0.3% | Jan 15, 2025 | A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now