2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31144 | LOW | 3.8 | 0.2% | Feb 14, 2025 | For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-over... |
| CVE-2024-8893 | HIGH | 7.3 | 0.3% | Feb 14, 2025 | Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows anyone in physical proximi... |
| CVE-2024-57790 | MEDIUM | 5.4 | 0.2% | Feb 14, 2025 | IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in ... |
| CVE-2024-56463 | MEDIUM | 4.8 | 0.2% | Feb 14, 2025 | IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrar... |
| CVE-2024-3220 | LOW | 2.3 | 0.5% | Feb 14, 2025 | There is a defect in the CPython standard library module “mimetypes” where on Windows the default list of known file loc... |
| CVE-2024-57778 | HIGH | 8.8 | 0.5% | Feb 14, 2025 | An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the serv... |
| CVE-2024-57725 | MEDIUM | 6.5 | 5.8% | Feb 14, 2025 | An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value wit... |
| CVE-2024-56973 | CRITICAL | 9.8 | 0.8% | Feb 14, 2025 | Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker ... |
| CVE-2024-56477 | MEDIUM | 6.5 | 0.5% | Feb 14, 2025 | IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the syst... |
| CVE-2024-52895 | MEDIUM | 6.5 | 0.4% | Feb 14, 2025 | IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities res... |
| CVE-2024-56180 | CRITICAL | 9.8 | 0.7% | Feb 14, 2025 | CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch wit... |
| CVE-2024-12651 | HIGH | 8.5 | 0.3% | Feb 14, 2025 | Exposed Dangerous Method or Function vulnerability in PTT Inc. HGS Mobile App allows Manipulating User-Controlled Variab... |
| CVE-2024-52500 | HIGH | 7.2 | 0.4% | Feb 14, 2025 | Missing Authorization vulnerability in monetagwp Monetag Official Plugin monetag-official allows Exploiting Incorrectly ... |
| CVE-2024-13152 | CRITICAL | 10 | 0.5% | Feb 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BSS Software Mobuy... |
| CVE-2024-13791 | MEDIUM | 4.9 | 0.6% | Feb 14, 2025 | Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the down... |
| CVE-2024-52577 | CRITICAL | 9 | 2.4% | Feb 14, 2025 | In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Igni... |
| CVE-2024-13735 | MEDIUM | 5.4 | 0.3% | Feb 14, 2025 | The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable ... |
| CVE-2024-9601 | MEDIUM | 5.4 | 0.3% | Feb 14, 2025 | The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’... |
| CVE-2024-57969 | MEDIUM | 4.3 | 0.2% | Feb 14, 2025 | app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search. |
| CVE-2024-7052 | MEDIUM | 4.8 | 0.3% | Feb 14, 2025 | The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-13692 | MEDIUM | 5.4 | 0.3% | Feb 14, 2025 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature... |
| CVE-2024-13641 | HIGH | 7.5 | 0.4% | Feb 14, 2025 | The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature... |
| CVE-2024-13493 | MEDIUM | 4.8 | 0.3% | Feb 14, 2025 | The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could a... |
| CVE-2024-2240 | HIGH | 7.2 | 0.5% | Feb 14, 2025 | Docker daemon in Brocade SANnav before SANnav 2.3.1b runs without auditing. The vulnerability could allow a remote authe... |
| CVE-2024-55904 | HIGH | 7.2 | 0.6% | Feb 14, 2025 | IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now