2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0339 | — | — | — | Feb 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-0198 | — | — | — | Feb 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-11890 | — | — | — | Feb 11, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-57178 | MEDIUM | 5.9 | 0.2% | Feb 10, 2025 | An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' pa... |
| CVE-2024-57177 | HIGH | 7.3 | 0.3% | Feb 10, 2025 | A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially ... |
| CVE-2024-8550 | HIGH | 7.5 | 0.5% | Feb 10, 2025 | A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4... |
| CVE-2024-54658 | MEDIUM | 6.5 | 0.5% | Feb 10, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, mac... |
| CVE-2024-46437 | MEDIUM | 6.5 | 1.1% | Feb 10, 2025 | A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unau... |
| CVE-2024-46436 | HIGH | 8.3 | 0.4% | Feb 10, 2025 | Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the ... |
| CVE-2024-46435 | HIGH | 8 | 0.8% | Feb 10, 2025 | A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote a... |
| CVE-2024-46434 | HIGH | 8.8 | 0.9% | Feb 10, 2025 | Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized rem... |
| CVE-2024-46433 | HIGH | 8.8 | 0.5% | Feb 10, 2025 | A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the... |
| CVE-2024-46432 | HIGH | 8.8 | 0.6% | Feb 10, 2025 | Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POS... |
| CVE-2024-46431 | HIGH | 8 | 0.4% | Feb 10, 2025 | Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can e... |
| CVE-2024-46430 | MEDIUM | 6.5 | 0.8% | Feb 10, 2025 | Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web manageme... |
| CVE-2024-46429 | HIGH | 8.8 | 0.6% | Feb 10, 2025 | A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access t... |
| CVE-2024-42513 | MEDIUM | 5.3 | 0.5% | Feb 10, 2025 | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application... |
| CVE-2024-42512 | HIGH | 8.6 | 0.5% | Feb 10, 2025 | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application... |
| CVE-2024-27859 | HIGH | 8.8 | 0.5% | Feb 10, 2025 | The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.... |
| CVE-2024-13059 | HIGH | 7.2 | 19.8% | Feb 10, 2025 | A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling ... |
| CVE-2024-13011 | CRITICAL | 9.8 | 0.8% | Feb 10, 2025 | The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation ... |
| CVE-2024-13010 | MEDIUM | 6.1 | 0.3% | Feb 10, 2025 | The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,... |
| CVE-2024-10649 | MEDIUM | 6.1 | 0.3% | Feb 10, 2025 | wandb/openui latest commit c945bb859979659add5f490a874140ad17c56a5d contains a vulnerability where unauthenticated endpo... |
| CVE-2024-57409 | MEDIUM | 4.8 | 0.3% | Feb 10, 2025 | A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers ... |
| CVE-2024-57408 | HIGH | 7.2 | 0.8% | Feb 10, 2025 | An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now