2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57773 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 ... |
| CVE-2024-57772 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 ... |
| CVE-2024-57771 | MEDIUM | 4.8 | 0.3% | Jan 16, 2025 | A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allow... |
| CVE-2024-41746 | MEDIUM | 6.1 | 0.2% | Jan 16, 2025 | IBM CICS TX Advanced 10.1, 11.1, and Standard 11.1 is vulnerable to stored cross-site scripting. This vulnerability allo... |
| CVE-2024-57161 | MEDIUM | 4.3 | 0.2% | Jan 16, 2025 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit... |
| CVE-2024-57160 | MEDIUM | 4.3 | 0.2% | Jan 16, 2025 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html. |
| CVE-2024-13387 | MEDIUM | 6.4 | 0.3% | Jan 16, 2025 | The WP Responsive Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprtabs' shor... |
| CVE-2024-13355 | MEDIUM | 5.4 | 0.4% | Jan 16, 2025 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited fi... |
| CVE-2024-12615 | MEDIUM | 6.5 | 0.5% | Jan 16, 2025 | The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX ac... |
| CVE-2024-12614 | MEDIUM | 4.3 | 0.4% | Jan 16, 2025 | The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-12427 | MEDIUM | 5.3 | 0.4% | Jan 16, 2025 | The Multi Step Form plugin for WordPress is vulnerable to unauthorized limited file upload due to a missing capability c... |
| CVE-2024-12226 | MEDIUM | 6.5 | 0.3% | Jan 16, 2025 | In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes s... |
| CVE-2024-11452 | MEDIUM | 6.4 | 0.3% | Jan 16, 2025 | The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-10789 | MEDIUM | 4.3 | 0.2% | Jan 16, 2025 | The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-10970 | MEDIUM | 5.4 | 0.3% | Jan 16, 2025 | The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution i... |
| CVE-2024-41454 | MEDIUM | 6.5 | 0.5% | Jan 15, 2025 | An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-... |
| CVE-2024-41453 | MEDIUM | 4.8 | 0.3% | Jan 15, 2025 | A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitr... |
| CVE-2024-39967 | MEDIUM | 6.5 | 0.3% | Jan 15, 2025 | Insecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command... |
| CVE-2024-36751 | MEDIUM | 6.5 | 0.5% | Jan 15, 2025 | An issue in parse-uri v1.0.9 allows attackers to cause a Regular expression Denial of Service (ReDoS) via a crafted URL. |
| CVE-2024-48122 | MEDIUM | 6.7 | 0.2% | Jan 15, 2025 | Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileg... |
| CVE-2024-48121 | MEDIUM | 6.5 | 0.2% | Jan 15, 2025 | The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. Thi... |
| CVE-2024-54540 | MEDIUM | 4.3 | 0.2% | Jan 15, 2025 | The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Proc... |
| CVE-2024-54535 | MEDIUM | 4.3 | 0.4% | Jan 15, 2025 | A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia ... |
| CVE-2024-54470 | MEDIUM | 4.6 | 0.3% | Jan 15, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPad... |
| CVE-2024-44136 | MEDIUM | 4.6 | 0.4% | Jan 15, 2025 | This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now