2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48589 | MEDIUM | 6.3 | 0.5% | Feb 6, 2025 | Cross Site Scripting vulnerability in Gilnei Moraes phpABook v.0.9 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-25883 | MEDIUM | 5.3 | 0.3% | Feb 6, 2025 | The mstatus register in RSD commit 3d13a updates incorrectly, leading to processing errors. |
| CVE-2024-56467 | LOW | 3.3 | 0.1% | Feb 6, 2025 | IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret... |
| CVE-2024-54171 | HIGH | 7.1 | 0.3% | Feb 6, 2025 | IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticat... |
| CVE-2024-57673 | MEDIUM | 5.5 | 0.2% | Feb 6, 2025 | An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module and Lin... |
| CVE-2024-57672 | MEDIUM | 5.5 | 0.1% | Feb 6, 2025 | An issue in floodlight v1.2 allows a local attacker to cause a denial of service via the Topology Manager module, Topolo... |
| CVE-2024-57426 | HIGH | 7.3 | 0.3% | Feb 6, 2025 | NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a mali... |
| CVE-2024-52892 | MEDIUM | 6.1 | 0.2% | Feb 6, 2025 | IBM Jazz for Service Management 1.1.3 through 1.1.3.23 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2024-47258 | HIGH | 8.1 | 0.1% | Feb 6, 2025 | 2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verif... |
| CVE-2024-47256 | MEDIUM | 6 | 0.1% | Feb 6, 2025 | Successful exploitation of this vulnerability could allow an attacker (who needs to have Admin access privileges) to rea... |
| CVE-2024-13417 | MEDIUM | 4.6 | 0.2% | Feb 6, 2025 | Specifically crafted payloads sent to the RFID reader could cause DoS of RFID reader. After the device is restarted, it ... |
| CVE-2024-57668 | HIGH | 8.8 | 0.6% | Feb 6, 2025 | In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability. |
| CVE-2024-57523 | MEDIUM | 4.5 | 0.5% | Feb 6, 2025 | Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attacke... |
| CVE-2024-13416 | MEDIUM | 4.3 | 0.3% | Feb 6, 2025 | Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system... |
| CVE-2024-57610 | HIGH | 7.5 | 1.1% | Feb 6, 2025 | A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user acco... |
| CVE-2024-36558 | HIGH | 7.5 | 0.1% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of ... |
| CVE-2024-36557 | MEDIUM | 6.6 | 0.2% | Feb 6, 2025 | The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Fo... |
| CVE-2024-36556 | CRITICAL | 9.1 | 0.3% | Feb 6, 2025 | Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R3... |
| CVE-2024-36555 | CRITICAL | 9.8 | 0.4% | Feb 6, 2025 | Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h an... |
| CVE-2024-36554 | CRITICAL | 9.8 | 0.4% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36... |
| CVE-2024-36553 | HIGH | 8.1 | 0.3% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack. |
| CVE-2024-57599 | MEDIUM | 4.8 | 0.3% | Feb 6, 2025 | Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a cra... |
| CVE-2024-57430 | CRITICAL | 9.8 | 0.8% | Feb 6, 2025 | An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers... |
| CVE-2024-57429 | MEDIUM | 5.4 | 0.3% | Feb 6, 2025 | A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.... |
| CVE-2024-57428 | CRITICAL | 9.3 | 0.7% | Feb 6, 2025 | A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized inp... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now