2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57407 | HIGH | 7.3 | 0.4% | Feb 10, 2025 | An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrar... |
| CVE-2024-54954 | HIGH | 8 | 0.4% | Feb 10, 2025 | OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department. |
| CVE-2024-48170 | MEDIUM | 5.4 | 0.2% | Feb 10, 2025 | PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the... |
| CVE-2024-57950 | MEDIUM | 5.5 | 0.2% | Feb 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Initialize denominator defaults to... |
| CVE-2024-12243 | MEDIUM | 5.3 | 1.2% | Feb 10, 2025 | A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libta... |
| CVE-2024-12133 | MEDIUM | 5.3 | 1.0% | Feb 10, 2025 | A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements ... |
| CVE-2024-11831 | MEDIUM | 5.4 | 1.1% | Feb 10, 2025 | A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not ... |
| CVE-2024-10334 | HIGH | 7.3 | 0.1% | Feb 10, 2025 | A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used. A... |
| CVE-2024-11621 | HIGH | 8.8 | 0.2% | Feb 10, 2025 | Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to... |
| CVE-2024-8685 | MEDIUM | 4.3 | 0.4% | Feb 10, 2025 | Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could... |
| CVE-2024-8684 | HIGH | 8.3 | 1.3% | Feb 10, 2025 | OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability... |
| CVE-2024-57949 | MEDIUM | 5.5 | 0.2% | Feb 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Don't enable interrupts in its_... |
| CVE-2024-13440 | HIGH | 8.2 | 0.4% | Feb 9, 2025 | The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all v... |
| CVE-2024-8377 | — | — | — | Feb 8, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-6909 | — | — | — | Feb 8, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-5183 | — | — | — | Feb 8, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-54176 | MEDIUM | 6.5 | 0.3% | Feb 8, 2025 | IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 thro... |
| CVE-2024-13850 | MEDIUM | 4.8 | 0.3% | Feb 8, 2025 | The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, a... |
| CVE-2024-55630 | MEDIUM | 5.5 | 0.3% | Feb 7, 2025 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into... |
| CVE-2024-57606 | HIGH | 7.5 | 0.5% | Feb 7, 2025 | SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker ... |
| CVE-2024-57357 | HIGH | 8 | 5.9% | Feb 7, 2025 | An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code... |
| CVE-2024-57279 | MEDIUM | 5.4 | 0.2% | Feb 7, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the LDAP User Manager <= ce92321, specifical... |
| CVE-2024-57278 | MEDIUM | 5.4 | 0.2% | Feb 7, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability exists in /webscan/sqlmap/index.html in QingScan <=v1.8.0. The vuln... |
| CVE-2024-55272 | HIGH | 7.5 | 0.5% | Feb 7, 2025 | An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function... |
| CVE-2024-55215 | CRITICAL | 9.8 | 1.3% | Feb 7, 2025 | An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization inter... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now