2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57841 | MEDIUM | 5.5 | 0.2% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in tcp_conn_request() If inet... |
| CVE-2024-57802 | MEDIUM | 5.5 | 0.2% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: netrom: check buffer length before accessing it Sy... |
| CVE-2024-54031 | MEDIUM | 5.5 | 0.2% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_hash: unaligned atomic read on s... |
| CVE-2024-53681 | MEDIUM | 5.5 | 0.2% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvmet: Don't overflow subsysnqn nvmet_root_discove... |
| CVE-2024-39282 | MEDIUM | 5.5 | 0.2% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: Fix FSM command timeout issue Whe... |
| CVE-2024-36476 | MEDIUM | 5.5 | 0.2% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Ensure 'ib_sge list' is accessible Move... |
| CVE-2024-13215 | MEDIUM | 4.3 | 0.5% | Jan 15, 2025 | The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,... |
| CVE-2024-11029 | MEDIUM | 5.5 | 0.2% | Jan 15, 2025 | A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence... |
| CVE-2024-12593 | MEDIUM | 6.4 | 0.4% | Jan 15, 2025 | The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-11851 | MEDIUM | 4.3 | 0.3% | Jan 15, 2025 | The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability ... |
| CVE-2024-35280 | MEDIUM | 6.1 | 0.3% | Jan 15, 2025 | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDe... |
| CVE-2024-12818 | MEDIUM | 6.4 | 0.3% | Jan 15, 2025 | The WP Smart TV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tv-video-player' sho... |
| CVE-2024-12423 | MEDIUM | 6.1 | 0.3% | Jan 15, 2025 | The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th... |
| CVE-2024-12403 | MEDIUM | 6.1 | 0.3% | Jan 15, 2025 | The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th... |
| CVE-2024-10775 | MEDIUM | 4.3 | 0.3% | Jan 15, 2025 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i... |
| CVE-2024-7322 | MEDIUM | 5.8 | 0.3% | Jan 15, 2025 | A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is re... |
| CVE-2024-11870 | MEDIUM | 6.4 | 0.3% | Jan 15, 2025 | The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-13394 | MEDIUM | 6.4 | 0.4% | Jan 15, 2025 | The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortco... |
| CVE-2024-13334 | MEDIUM | 6.1 | 0.3% | Jan 15, 2025 | The Car Demon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_condition' parameter ... |
| CVE-2024-57760 | MEDIUM | 6.5 | 0.4% | Jan 15, 2025 | JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CG... |
| CVE-2024-53277 | MEDIUM | 5.4 | 0.3% | Jan 14, 2025 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HT... |
| CVE-2024-47605 | MEDIUM | 5.4 | 1.1% | Jan 14, 2025 | silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functional... |
| CVE-2024-50861 | MEDIUM | 6.1 | 0.8% | Jan 14, 2025 | The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious cod... |
| CVE-2024-50859 | MEDIUM | 4.8 | 0.8% | Jan 14, 2025 | The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly forma... |
| CVE-2024-50857 | MEDIUM | 4.8 | 1.2% | Jan 14, 2025 | The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and en... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now