2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12971 | HIGH | 8.8 | 59.4% | Mar 17, 2025 | Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affec... |
| CVE-2024-13602 | MEDIUM | 4.8 | 0.2% | Mar 16, 2025 | The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-13126 | MEDIUM | 4.6 | 0.5% | Mar 16, 2025 | The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htac... |
| CVE-2024-58103 | MEDIUM | 5.8 | 0.4% | Mar 16, 2025 | Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReade... |
| CVE-2024-13497 | MEDIUM | 6.1 | 0.3% | Mar 15, 2025 | The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable t... |
| CVE-2024-13847 | — | — | — | Mar 15, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-12336 | MEDIUM | 6.5 | 0.3% | Mar 15, 2025 | The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of ... |
| CVE-2024-54449 | HIGH | 8.8 | 0.6% | Mar 14, 2025 | The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticat... |
| CVE-2024-54448 | HIGH | 7.2 | 0.5% | Mar 14, 2025 | The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying ... |
| CVE-2024-54447 | HIGH | 7.1 | 0.3% | Mar 14, 2025 | Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time... |
| CVE-2024-54446 | HIGH | 7.1 | 0.3% | Mar 14, 2025 | Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a ... |
| CVE-2024-54445 | HIGH | 8.7 | 0.3% | Mar 14, 2025 | Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-base... |
| CVE-2024-29409 | MEDIUM | 5.5 | 0.3% | Mar 14, 2025 | File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Typ... |
| CVE-2024-12245 | HIGH | 8.7 | 0.3% | Mar 14, 2025 | Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-bas... |
| CVE-2024-12020 | MEDIUM | 6.1 | 0.2% | Mar 14, 2025 | There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthentica... |
| CVE-2024-12019 | HIGH | 7.1 | 0.4% | Mar 14, 2025 | The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read... |
| CVE-2024-55594 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7... |
| CVE-2024-40585 | MEDIUM | 6.5 | 0.3% | Mar 14, 2025 | An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2... |
| CVE-2024-47573 | MEDIUM | 6.5 | 0.2% | Mar 14, 2025 | An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2... |
| CVE-2024-46662 | HIGH | 8.8 | 2.1% | Mar 14, 2025 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions ... |
| CVE-2024-45643 | HIGH | 7.5 | 0.2% | Mar 14, 2025 | IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt ... |
| CVE-2024-45638 | MEDIUM | 4.4 | 0.1% | Mar 14, 2025 | IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user. |
| CVE-2024-40590 | MEDIUM | 4.8 | 0.2% | Mar 14, 2025 | An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, versio... |
| CVE-2024-13773 | HIGH | 7.5 | 0.3% | Mar 14, 2025 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information... |
| CVE-2024-13772 | MEDIUM | 5.9 | 0.3% | Mar 14, 2025 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now