2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57974 | MEDIUM | 4.7 | 0.1% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: udp: Deal with race between UDP socket address chan... |
| CVE-2024-57973 | MEDIUM | 5.5 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 3... |
| CVE-2024-57953 | MEDIUM | 5.5 | 0.2% | Feb 27, 2025 | In the Linux kernel, the following vulnerability has been resolved: rtc: tps6594: Fix integer overflow on 32bit systems... |
| CVE-2024-57040 | CRITICAL | 9.8 | 1.1% | Feb 26, 2025 | TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a ... |
| CVE-2024-55581 | HIGH | 7.4 | 0.3% | Feb 26, 2025 | When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-... |
| CVE-2024-53573 | CRITICAL | 9.8 | 0.5% | Feb 26, 2025 | Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints ... |
| CVE-2024-57423 | MEDIUM | 6.1 | 0.5% | Feb 26, 2025 | A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary co... |
| CVE-2024-50696 | HIGH | 7.5 | 0.2% | Feb 26, 2025 | SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a speci... |
| CVE-2024-50693 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50691 | HIGH | 7.4 | 0.2% | Feb 26, 2025 | SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app expli... |
| CVE-2024-50689 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50688 | CRITICAL | 9.8 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regar... |
| CVE-2024-50687 | CRITICAL | 9.1 | 0.4% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50686 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50685 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) v... |
| CVE-2024-50684 | MEDIUM | 6.5 | 0.3% | Feb 26, 2025 | SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient ... |
| CVE-2024-53427 | HIGH | 8.1 | 0.4% | Feb 26, 2025 | decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which ha... |
| CVE-2024-46226 | MEDIUM | 4.8 | 0.2% | Feb 26, 2025 | A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary Jav... |
| CVE-2024-52925 | MEDIUM | 6.8 | 0.3% | Feb 26, 2025 | In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unl... |
| CVE-2024-6810 | MEDIUM | 4.4 | 0.5% | Feb 26, 2025 | The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin... |
| CVE-2024-47053 | HIGH | 7.7 | 0.7% | Feb 26, 2025 | This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw c... |
| CVE-2024-47051 | CRITICAL | 9.9 | 1.7% | Feb 26, 2025 | This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabili... |
| CVE-2024-39441 | HIGH | 8.4 | 0.1% | Feb 26, 2025 | In wifi display, there is a possible missing permission check. This could lead to local escalation of privilege with no ... |
| CVE-2024-13803 | MEDIUM | 5.4 | 0.4% | Feb 26, 2025 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-13678 | MEDIUM | 6.1 | 0.4% | Feb 26, 2025 | The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now