2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11283 | HIGH | 7.5 | 0.4% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th... |
| CVE-2024-55549 | HIGH | 7.8 | 0.3% | Mar 14, 2025 | xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. |
| CVE-2024-55060 | MEDIUM | 6.1 | 0.5% | Mar 13, 2025 | A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to exe... |
| CVE-2024-30143 | MEDIUM | 4.3 | 0.4% | Mar 13, 2025 | HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing... |
| CVE-2024-9042 | MEDIUM | 5.9 | 1.4% | Mar 13, 2025 | This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the aff... |
| CVE-2024-53406 | HIGH | 8.8 | 0.6% | Mar 13, 2025 | Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection p... |
| CVE-2024-12858 | — | — | — | Mar 13, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. *** Duplicate of CVE-2025-2... |
| CVE-2024-57062 | MEDIUM | 6.7 | 0.1% | Mar 13, 2025 | An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive info... |
| CVE-2024-55198 | MEDIUM | 5.3 | 0.4% | Mar 13, 2025 | User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery funct... |
| CVE-2024-57348 | MEDIUM | 6.1 | 0.3% | Mar 13, 2025 | Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary c... |
| CVE-2024-28803 | MEDIUM | 6.1 | 0.3% | Mar 13, 2025 | Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote att... |
| CVE-2024-22880 | MEDIUM | 4.7 | 0.3% | Mar 13, 2025 | Cross Site Scripting vulnerability in Zadarma Zadarma extension v.1.0.11 allows a remote attacker to execute a arbitrary... |
| CVE-2024-10942 | HIGH | 7.5 | 0.5% | Mar 13, 2025 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,... |
| CVE-2024-8402 | HIGH | 7.4 | 0.2% | Mar 13, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from... |
| CVE-2024-7296 | LOW | 2.7 | 0.3% | Mar 13, 2025 | An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 pr... |
| CVE-2024-13891 | HIGH | 7.1 | 0.3% | Mar 13, 2025 | The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13885 | HIGH | 7.1 | 0.3% | Mar 13, 2025 | The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2024-13884 | HIGH | 7.1 | 0.3% | Mar 13, 2025 | The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-13054 | MEDIUM | 6.5 | 0.6% | Mar 13, 2025 | An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17... |
| CVE-2024-12380 | HIGH | 7.5 | 0.5% | Mar 13, 2025 | An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting f... |
| CVE-2024-13887 | MEDIUM | 5.3 | 0.3% | Mar 13, 2025 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Di... |
| CVE-2024-13703 | MEDIUM | 4.3 | 0.3% | Mar 13, 2025 | The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a mi... |
| CVE-2024-26290 | HIGH | 8.7 | 0.5% | Mar 12, 2025 | Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Av... |
| CVE-2024-34398 | MEDIUM | 4.2 | 0.2% | Mar 12, 2025 | An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated... |
| CVE-2024-27763 | MEDIUM | 5.3 | 0.2% | Mar 12, 2025 | XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostna... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now