2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8402 | HIGH | 7.4 | 0.2% | Mar 13, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from... |
| CVE-2024-7296 | LOW | 2.7 | 0.3% | Mar 13, 2025 | An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 pr... |
| CVE-2024-13891 | HIGH | 7.1 | 0.3% | Mar 13, 2025 | The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13885 | HIGH | 7.1 | 0.3% | Mar 13, 2025 | The WP e-Customers Beta WordPress plugin through 0.0.1 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2024-13884 | HIGH | 7.1 | 0.3% | Mar 13, 2025 | The Limit Bio WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-13054 | MEDIUM | 6.5 | 0.6% | Mar 13, 2025 | An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17... |
| CVE-2024-12380 | HIGH | 7.5 | 0.5% | Mar 13, 2025 | An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting f... |
| CVE-2024-13887 | MEDIUM | 5.3 | 0.3% | Mar 13, 2025 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Di... |
| CVE-2024-13703 | MEDIUM | 4.3 | 0.3% | Mar 13, 2025 | The CRM and Lead Management by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a mi... |
| CVE-2024-26290 | HIGH | 8.7 | 0.5% | Mar 12, 2025 | Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Av... |
| CVE-2024-34398 | MEDIUM | 4.2 | 0.2% | Mar 12, 2025 | An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated... |
| CVE-2024-27763 | MEDIUM | 5.3 | 0.2% | Mar 12, 2025 | XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostna... |
| CVE-2024-52362 | MEDIUM | 6.5 | 0.4% | Mar 12, 2025 | IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11... |
| CVE-2024-10838 | CRITICAL | 9.1 | 0.9% | Mar 12, 2025 | An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This m... |
| CVE-2024-13872 | HIGH | 7.5 | 0.2% | Mar 12, 2025 | Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Int... |
| CVE-2024-13871 | HIGH | 8.8 | 0.8% | Mar 12, 2025 | A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (fir... |
| CVE-2024-13870 | MEDIUM | 5.7 | 0.2% | Mar 12, 2025 | An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows... |
| CVE-2024-58089 | MEDIUM | 5.5 | 0.2% | Mar 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double accounting race when btrfs_run_de... |
| CVE-2024-58088 | MEDIUM | 5.5 | 0.2% | Mar 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix deadlock when freeing cgroup storage The ... |
| CVE-2024-13446 | CRITICAL | 9.8 | 0.4% | Mar 12, 2025 | The Workreap plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and ... |
| CVE-2024-13430 | MEDIUM | 4.3 | 0.3% | Mar 12, 2025 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Information Exposure i... |
| CVE-2024-58087 | HIGH | 8.1 | 0.4% | Mar 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix racy issue from session lookup and expir... |
| CVE-2024-13838 | LOW | 3.8 | 0.3% | Mar 12, 2025 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera... |
| CVE-2024-12589 | MEDIUM | 5.4 | 0.2% | Mar 12, 2025 | The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Base... |
| CVE-2024-13498 | MEDIUM | 5.3 | 0.4% | Mar 12, 2025 | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Info... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now