2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13777 | CRITICAL | 9.8 | 0.6% | Mar 5, 2025 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in... |
| CVE-2024-41147 | CRITICAL | 9.8 | 0.7% | Mar 4, 2025 | An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio ... |
| CVE-2024-50707 | CRITICAL | 10 | 0.8% | Mar 4, 2025 | Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to exec... |
| CVE-2024-50704 | CRITICAL | 10 | 0.9% | Mar 4, 2025 | Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to exec... |
| CVE-2024-11957 | CRITICAL | 9.3 | 0.1% | Mar 4, 2025 | Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12... |
| CVE-2024-50706 | CRITICAL | 9.8 | 0.5% | Mar 4, 2025 | Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbi... |
| CVE-2024-55532 | CRITICAL | 9.8 | 0.7% | Mar 3, 2025 | Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Use... |
| CVE-2024-8262 | CRITICAL | 9.8 | 0.6% | Mar 3, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allo... |
| CVE-2024-47092 | CRITICAL | 9.8 | 0.3% | Mar 3, 2025 | Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1 |
| CVE-2024-12824 | CRITICAL | 9.8 | 2.2% | Mar 1, 2025 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in ... |
| CVE-2024-1509 | CRITICAL | 9.1 | 0.3% | Feb 28, 2025 | Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response h... |
| CVE-2024-9193 | CRITICAL | 9.8 | 3.1% | Feb 28, 2025 | The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all vers... |
| CVE-2024-8425 | CRITICAL | 9.8 | 3.9% | Feb 28, 2025 | The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file... |
| CVE-2024-8420 | CRITICAL | 9.8 | 0.5% | Feb 28, 2025 | The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. Th... |
| CVE-2024-37567 | CRITICAL | 9.1 | 0.3% | Feb 27, 2025 | Infoblox NIOS through 8.6.4 has Improper Access Control for Grids. |
| CVE-2024-37566 | CRITICAL | 9.8 | 0.4% | Feb 27, 2025 | Infoblox NIOS through 8.6.4 has Improper Authentication for Grids. |
| CVE-2024-36047 | CRITICAL | 9.8 | 0.4% | Feb 27, 2025 | Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation. |
| CVE-2024-36046 | CRITICAL | 9.8 | 0.4% | Feb 27, 2025 | Infoblox NIOS through 8.6.4 executes with more privileges than required. |
| CVE-2024-38292 | CRITICAL | 9.8 | 0.5% | Feb 27, 2025 | In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which ma... |
| CVE-2024-55160 | CRITICAL | 9.8 | 0.5% | Feb 27, 2025 | GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/op... |
| CVE-2024-51139 | CRITICAL | 9.8 | 1.1% | Feb 27, 2025 | Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862... |
| CVE-2024-51138 | CRITICAL | 9.8 | 1.1% | Feb 27, 2025 | Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3... |
| CVE-2024-53944 | CRITICAL | 9.8 | 39.2% | Feb 27, 2025 | An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B ... |
| CVE-2024-13148 | CRITICAL | 9.8 | 0.4% | Feb 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter ... |
| CVE-2024-10918 | CRITICAL | 9.8 | 0.4% | Feb 27, 2025 | Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus re... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now