2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11934 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-11899 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Slider Pro Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sliderpro' short... |
| CVE-2024-11777 | MEDIUM | 6.4 | 0.3% | Jan 7, 2025 | The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_for... |
| CVE-2024-11437 | MEDIUM | 4.9 | 0.5% | Jan 7, 2025 | The Timeline Designer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, a... |
| CVE-2024-54764 | MEDIUM | 6.5 | 1.0% | Jan 6, 2025 | An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensit... |
| CVE-2024-54763 | MEDIUM | 6.5 | 0.7% | Jan 6, 2025 | An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensiti... |
| CVE-2024-53936 | MEDIUM | 6.3 | 0.2% | Jan 6, 2025 | The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any applicati... |
| CVE-2024-53935 | MEDIUM | 6.5 | 0.2% | Jan 6, 2025 | The com.callos14.callscreen.colorphone (aka iCall OS17 - Color Phone Flash) application through 4.3 for Android enables ... |
| CVE-2024-53933 | MEDIUM | 6.3 | 0.2% | Jan 6, 2025 | The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Andr... |
| CVE-2024-51741 | MEDIUM | 4.4 | 0.3% | Jan 6, 2025 | Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat... |
| CVE-2024-55075 | MEDIUM | 5.3 | 0.5% | Jan 6, 2025 | Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not sh... |
| CVE-2024-55408 | MEDIUM | 5.3 | 0.2% | Jan 6, 2025 | An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality uti... |
| CVE-2024-46209 | MEDIUM | 5.4 | 0.4% | Jan 6, 2025 | A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attacke... |
| CVE-2024-35498 | MEDIUM | 6.1 | 0.4% | Jan 6, 2025 | A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via... |
| CVE-2024-55626 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-46073 | MEDIUM | 6.1 | 0.4% | Jan 6, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is... |
| CVE-2024-56769 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: dib3000mb: fix uninit-value i... |
| CVE-2024-56768 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_get_smp_processor_id() on !CONFIG_SMP ... |
| CVE-2024-56767 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_xdmac: avoid null_prt_deref in at_xdm... |
| CVE-2024-56763 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent bad count for tracing_cpumask_writ... |
| CVE-2024-56761 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: x86/fred: Clear WFE in missing-ENDBRANCH #CPs An i... |
| CVE-2024-56760 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: PCI/MSI: Handle lack of irqdomain gracefully Alexa... |
| CVE-2024-56758 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: check folio mapping after unlock in relocate... |
| CVE-2024-56757 | MEDIUM | 5.5 | 0.2% | Jan 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow w... |
| CVE-2024-47475 | MEDIUM | 5.5 | 0.1% | Jan 6, 2025 | Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerab... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now