2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13771 | MEDIUM | 5.9 | 0.4% | Mar 14, 2025 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass... |
| CVE-2024-12810 | HIGH | 8.1 | 0.3% | Mar 14, 2025 | The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modificat... |
| CVE-2024-26006 | MEDIUM | 6.1 | 0.6% | Mar 14, 2025 | An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below... |
| CVE-2024-8176 | HIGH | 7.5 | 1.3% | Mar 14, 2025 | A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XM... |
| CVE-2024-13407 | MEDIUM | 6.5 | 0.3% | Mar 14, 2025 | The Omnipress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.4 via... |
| CVE-2024-13321 | CRITICAL | 9.8 | 0.4% | Mar 14, 2025 | The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to... |
| CVE-2024-13824 | CRITICAL | 9.8 | 0.6% | Mar 14, 2025 | The CiyaShop - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to PHP Object Injection in all versions ... |
| CVE-2024-13913 | HIGH | 8.8 | 2.4% | Mar 14, 2025 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2024-13376 | HIGH | 8.8 | 0.3% | Mar 14, 2025 | The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat... |
| CVE-2024-11286 | CRITICAL | 9.8 | 0.6% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th... |
| CVE-2024-11285 | CRITICAL | 9.8 | 0.4% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an... |
| CVE-2024-11284 | CRITICAL | 9.8 | 0.5% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, an... |
| CVE-2024-11283 | HIGH | 7.5 | 0.4% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th... |
| CVE-2024-55549 | HIGH | 7.8 | 0.3% | Mar 14, 2025 | xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. |
| CVE-2024-55060 | MEDIUM | 6.1 | 0.5% | Mar 13, 2025 | A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to exe... |
| CVE-2024-30143 | MEDIUM | 4.3 | 0.4% | Mar 13, 2025 | HCL AppScan Traffic Recorder fails to adequately neutralize special characters within the filename, potentially allowing... |
| CVE-2024-9042 | MEDIUM | 5.9 | 1.4% | Mar 13, 2025 | This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the aff... |
| CVE-2024-53406 | HIGH | 8.8 | 0.6% | Mar 13, 2025 | Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection p... |
| CVE-2024-12858 | — | — | — | Mar 13, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. *** Duplicate of CVE-2025-2... |
| CVE-2024-57062 | MEDIUM | 6.7 | 0.1% | Mar 13, 2025 | An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive info... |
| CVE-2024-55198 | MEDIUM | 5.3 | 0.4% | Mar 13, 2025 | User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery funct... |
| CVE-2024-57348 | MEDIUM | 6.1 | 0.3% | Mar 13, 2025 | Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary c... |
| CVE-2024-28803 | MEDIUM | 6.1 | 0.3% | Mar 13, 2025 | Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote att... |
| CVE-2024-22880 | MEDIUM | 4.7 | 0.3% | Mar 13, 2025 | Cross Site Scripting vulnerability in Zadarma Zadarma extension v.1.0.11 allows a remote attacker to execute a arbitrary... |
| CVE-2024-10942 | HIGH | 7.5 | 0.5% | Mar 13, 2025 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now