2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53944 | CRITICAL | 9.8 | 39.2% | Feb 27, 2025 | An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B ... |
| CVE-2024-13148 | CRITICAL | 9.8 | 0.4% | Feb 27, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter ... |
| CVE-2024-10918 | CRITICAL | 9.8 | 0.4% | Feb 27, 2025 | Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus re... |
| CVE-2024-13905 | CRITICAL | 9.1 | 0.3% | Feb 27, 2025 | The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin... |
| CVE-2024-57040 | CRITICAL | 9.8 | 1.1% | Feb 26, 2025 | TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a ... |
| CVE-2024-53573 | CRITICAL | 9.8 | 0.5% | Feb 26, 2025 | Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints ... |
| CVE-2024-50693 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50689 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50688 | CRITICAL | 9.8 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regar... |
| CVE-2024-50687 | CRITICAL | 9.1 | 0.4% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50686 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50685 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) v... |
| CVE-2024-47051 | CRITICAL | 9.9 | 1.7% | Feb 26, 2025 | This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabili... |
| CVE-2024-30150 | CRITICAL | 9.1 | 0.3% | Feb 25, 2025 | HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lea... |
| CVE-2024-56525 | CRITICAL | 9.8 | 0.4% | Feb 24, 2025 | In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journ... |
| CVE-2024-53544 | CRITICAL | 9.8 | 0.4% | Feb 24, 2025 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability... |
| CVE-2024-54820 | CRITICAL | 9.8 | 1.1% | Feb 24, 2025 | XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login ... |
| CVE-2024-56897 | CRITICAL | 9.8 | 0.7% | Feb 24, 2025 | Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API ... |
| CVE-2024-54756 | CRITICAL | 9.8 | 2.8% | Feb 20, 2025 | A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to exe... |
| CVE-2024-57401 | CRITICAL | 9.8 | 0.8% | Feb 20, 2025 | SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code... |
| CVE-2024-13792 | CRITICAL | 9.8 | 0.5% | Feb 20, 2025 | The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode executi... |
| CVE-2024-13789 | CRITICAL | 9.8 | 0.8% | Feb 20, 2025 | The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via de... |
| CVE-2024-37361 | CRITICAL | 9.9 | 0.5% | Feb 20, 2025 | The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-5... |
| CVE-2024-56171 | CRITICAL | 9.8 | 1.1% | Feb 18, 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleID... |
| CVE-2024-56000 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now