2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29409 | MEDIUM | 5.5 | 0.3% | Mar 14, 2025 | File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Typ... |
| CVE-2024-12245 | HIGH | 8.7 | 0.3% | Mar 14, 2025 | Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-bas... |
| CVE-2024-12020 | MEDIUM | 6.1 | 0.2% | Mar 14, 2025 | There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthentica... |
| CVE-2024-12019 | HIGH | 7.1 | 0.4% | Mar 14, 2025 | The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read... |
| CVE-2024-55594 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7... |
| CVE-2024-40585 | MEDIUM | 6.5 | 0.3% | Mar 14, 2025 | An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2... |
| CVE-2024-47573 | MEDIUM | 6.5 | 0.2% | Mar 14, 2025 | An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2... |
| CVE-2024-46662 | HIGH | 8.8 | 2.1% | Mar 14, 2025 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions ... |
| CVE-2024-45643 | HIGH | 7.5 | 0.2% | Mar 14, 2025 | IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt ... |
| CVE-2024-45638 | MEDIUM | 4.4 | 0.1% | Mar 14, 2025 | IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user. |
| CVE-2024-40590 | MEDIUM | 4.8 | 0.2% | Mar 14, 2025 | An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, versio... |
| CVE-2024-13773 | HIGH | 7.5 | 0.3% | Mar 14, 2025 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information... |
| CVE-2024-13772 | MEDIUM | 5.9 | 0.3% | Mar 14, 2025 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass... |
| CVE-2024-13771 | MEDIUM | 5.9 | 0.4% | Mar 14, 2025 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass... |
| CVE-2024-12810 | HIGH | 8.1 | 0.3% | Mar 14, 2025 | The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modificat... |
| CVE-2024-26006 | MEDIUM | 6.1 | 0.6% | Mar 14, 2025 | An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below... |
| CVE-2024-8176 | HIGH | 7.5 | 1.6% | Mar 14, 2025 | A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XM... |
| CVE-2024-13407 | MEDIUM | 6.5 | 0.3% | Mar 14, 2025 | The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via... |
| CVE-2024-13321 | CRITICAL | 9.8 | 0.4% | Mar 14, 2025 | The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to... |
| CVE-2024-13824 | CRITICAL | 9.8 | 0.6% | Mar 14, 2025 | The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions ... |
| CVE-2024-13913 | HIGH | 8.8 | 2.4% | Mar 14, 2025 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2024-13376 | HIGH | 8.8 | 0.3% | Mar 14, 2025 | The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat... |
| CVE-2024-11286 | CRITICAL | 9.8 | 0.6% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th... |
| CVE-2024-11285 | CRITICAL | 9.8 | 0.4% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an... |
| CVE-2024-11284 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now