2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13843 | MEDIUM | 4.4 | 0.3% | Feb 11, 2025 | Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before versio... |
| CVE-2024-13842 | MEDIUM | 4.4 | 0.3% | Feb 11, 2025 | A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows... |
| CVE-2024-13830 | MEDIUM | 6.1 | 0.6% | Feb 11, 2025 | Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a... |
| CVE-2024-13813 | HIGH | 7.1 | 0.2% | Feb 11, 2025 | Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to d... |
| CVE-2024-12797 | MEDIUM | 6.3 | 2.4% | Feb 11, 2025 | Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server ... |
| CVE-2024-12058 | MEDIUM | 4.9 | 0.9% | Feb 11, 2025 | External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version... |
| CVE-2024-11771 | MEDIUM | 5.3 | 0.9% | Feb 11, 2025 | Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted function... |
| CVE-2024-10644 | HIGH | 7.2 | 2.2% | Feb 11, 2025 | Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows ... |
| CVE-2024-33659 | HIGH | 8.8 | 0.2% | Feb 11, 2025 | AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker... |
| CVE-2024-12366 | CRITICAL | 9.8 | 1.2% | Feb 11, 2025 | PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that c... |
| CVE-2024-54090 | MEDIUM | 6 | 0.4% | Feb 11, 2025 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v... |
| CVE-2024-54089 | HIGH | 8.7 | 0.2% | Feb 11, 2025 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v... |
| CVE-2024-54015 | HIGH | 8.7 | 0.5% | Feb 11, 2025 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All ve... |
| CVE-2024-53977 | HIGH | 7.8 | 0.1% | Feb 11, 2025 | A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example se... |
| CVE-2024-53651 | MEDIUM | 5.1 | 0.2% | Feb 11, 2025 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),... |
| CVE-2024-53648 | HIGH | 7 | 0.3% | Feb 11, 2025 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All ve... |
| CVE-2024-45386 | HIGH | 8.8 | 0.5% | Feb 11, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Up... |
| CVE-2024-23814 | MEDIUM | 6.9 | 0.6% | Feb 11, 2025 | The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory reso... |
| CVE-2024-13506 | MEDIUM | 6.4 | 0.4% | Feb 11, 2025 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ... |
| CVE-2024-52612 | MEDIUM | 4.8 | 0.5% | Feb 11, 2025 | SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient ... |
| CVE-2024-52611 | LOW | 3.5 | 0.3% | Feb 11, 2025 | The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the dat... |
| CVE-2024-52606 | CRITICAL | 9.8 | 2.3% | Feb 11, 2025 | SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied al... |
| CVE-2024-45718 | MEDIUM | 4.6 | 0.2% | Feb 11, 2025 | Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a l... |
| CVE-2024-28989 | MEDIUM | 5.5 | 0.3% | Feb 11, 2025 | SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive in... |
| CVE-2024-13643 | HIGH | 8.8 | 0.6% | Feb 11, 2025 | The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now