2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13905 | CRITICAL | 9.1 | 0.3% | Feb 27, 2025 | The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin... |
| CVE-2024-57040 | CRITICAL | 9.8 | 1.1% | Feb 26, 2025 | TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a ... |
| CVE-2024-53573 | CRITICAL | 9.8 | 0.5% | Feb 26, 2025 | Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints ... |
| CVE-2024-50693 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50689 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50688 | CRITICAL | 9.8 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regar... |
| CVE-2024-50687 | CRITICAL | 9.1 | 0.4% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50686 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi... |
| CVE-2024-50685 | CRITICAL | 9.1 | 0.5% | Feb 26, 2025 | SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) v... |
| CVE-2024-47051 | CRITICAL | 9.9 | 1.7% | Feb 26, 2025 | This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabili... |
| CVE-2024-30150 | CRITICAL | 9.1 | 0.3% | Feb 25, 2025 | HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lea... |
| CVE-2024-56525 | CRITICAL | 9.8 | 0.4% | Feb 24, 2025 | In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journ... |
| CVE-2024-53544 | CRITICAL | 9.8 | 0.4% | Feb 24, 2025 | NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability... |
| CVE-2024-54820 | CRITICAL | 9.8 | 1.1% | Feb 24, 2025 | XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login ... |
| CVE-2024-56897 | CRITICAL | 9.8 | 0.7% | Feb 24, 2025 | Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API ... |
| CVE-2024-54756 | CRITICAL | 9.8 | 2.8% | Feb 20, 2025 | A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to exe... |
| CVE-2024-57401 | CRITICAL | 9.8 | 0.8% | Feb 20, 2025 | SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code... |
| CVE-2024-13792 | CRITICAL | 9.8 | 0.5% | Feb 20, 2025 | The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode executi... |
| CVE-2024-13789 | CRITICAL | 9.8 | 0.8% | Feb 20, 2025 | The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via de... |
| CVE-2024-37361 | CRITICAL | 9.9 | 0.5% | Feb 20, 2025 | The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-5... |
| CVE-2024-56171 | CRITICAL | 9.8 | 1.1% | Feb 18, 2025 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleID... |
| CVE-2024-56000 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issu... |
| CVE-2024-55460 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election Syste... |
| CVE-2024-39327 | CRITICAL | 9.9 | 0.4% | Feb 18, 2025 | Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing... |
| CVE-2024-57045 | CRITICAL | 9.8 | 32.3% | Feb 18, 2025 | A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now