2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21830 | MEDIUM | 6.7 | 0.2% | Feb 12, 2025 | Uncontrolled search path in some Intel(R) VPL software before version 2023.4.0 may allow an authenticated user to potent... |
| CVE-2024-12673 | HIGH | 8.5 | 0.2% | Feb 12, 2025 | An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devic... |
| CVE-2024-6097 | MEDIUM | 5.3 | 0.5% | Feb 12, 2025 | In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local t... |
| CVE-2024-11629 | MEDIUM | 6.5 | 0.4% | Feb 12, 2025 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, th... |
| CVE-2024-11628 | HIGH | 7.2 | 0.7% | Feb 12, 2025 | In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties wi... |
| CVE-2024-9870 | HIGH | 8.8 | 0.4% | Feb 12, 2025 | An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior... |
| CVE-2024-12629 | HIGH | 7.2 | 0.7% | Feb 12, 2025 | In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within t... |
| CVE-2024-11343 | HIGH | 8.8 | 0.6% | Feb 12, 2025 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can le... |
| CVE-2024-54160 | MEDIUM | 6.4 | 0.6% | Feb 12, 2025 | dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because ... |
| CVE-2024-12379 | MEDIUM | 6.5 | 0.5% | Feb 12, 2025 | A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4... |
| CVE-2024-12251 | HIGH | 7.8 | 0.5% | Feb 12, 2025 | In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through impro... |
| CVE-2024-57952 | MEDIUM | 5.5 | 0.2% | Feb 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: Revert "libfs: fix infinite directory reads for off... |
| CVE-2024-57951 | HIGH | 7.8 | 0.2% | Feb 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: hrtimers: Handle CPU state correctly on hotplug Co... |
| CVE-2024-23563 | MEDIUM | 4.4 | 0.1% | Feb 12, 2025 | HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive in... |
| CVE-2024-10322 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads... |
| CVE-2024-13532 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | The Small Package Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and '... |
| CVE-2024-13480 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | The LTL Freight Quotes – For Customers of FedEx Freight plugin for WordPress is vulnerable to SQL Injection via the 'edi... |
| CVE-2024-13477 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | The LTL Freight Quotes – Unishippers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' param... |
| CVE-2024-12386 | MEDIUM | 5.4 | 0.2% | Feb 12, 2025 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-10960 | HIGH | 8.8 | 0.9% | Feb 12, 2025 | The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio... |
| CVE-2024-32838 | HIGH | 8.8 | 1.3% | Feb 12, 2025 | SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before... |
| CVE-2024-13531 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | The ShipEngine Shipping Quotes plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all ve... |
| CVE-2024-13528 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versi... |
| CVE-2024-13490 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | The LTL Freight Quotes – XPO Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship... |
| CVE-2024-13475 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | The Small Package Quotes – UPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now