2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13416 | MEDIUM | 4.3 | 0.3% | Feb 6, 2025 | Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system... |
| CVE-2024-57610 | HIGH | 7.5 | 1.1% | Feb 6, 2025 | A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user acco... |
| CVE-2024-36558 | HIGH | 7.5 | 0.1% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of ... |
| CVE-2024-36557 | MEDIUM | 6.6 | 0.2% | Feb 6, 2025 | The device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Fo... |
| CVE-2024-36556 | CRITICAL | 9.1 | 0.3% | Feb 6, 2025 | Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R3... |
| CVE-2024-36555 | CRITICAL | 9.8 | 0.4% | Feb 6, 2025 | Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h an... |
| CVE-2024-36554 | CRITICAL | 9.8 | 0.4% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36... |
| CVE-2024-36553 | HIGH | 8.1 | 0.3% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack. |
| CVE-2024-57599 | MEDIUM | 4.8 | 0.3% | Feb 6, 2025 | Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a cra... |
| CVE-2024-57430 | CRITICAL | 9.8 | 0.8% | Feb 6, 2025 | An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers... |
| CVE-2024-57429 | MEDIUM | 5.4 | 0.3% | Feb 6, 2025 | A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.... |
| CVE-2024-57428 | CRITICAL | 9.3 | 0.7% | Feb 6, 2025 | A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized inp... |
| CVE-2024-57427 | MEDIUM | 6.1 | 0.4% | Feb 6, 2025 | PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improper... |
| CVE-2024-43779 | MEDIUM | 6.5 | 0.8% | Feb 6, 2025 | An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. ... |
| CVE-2024-39272 | HIGH | 8.2 | 0.5% | Feb 6, 2025 | A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.... |
| CVE-2024-39033 | HIGH | 7.5 | 0.3% | Feb 6, 2025 | In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows u... |
| CVE-2024-13614 | MEDIUM | 5.3 | 0.1% | Feb 6, 2025 | Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Ligh... |
| CVE-2024-43811 | — | — | — | Feb 6, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2024-24911 | HIGH | 7.5 | 0.4% | Feb 6, 2025 | In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, ... |
| CVE-2024-57962 | HIGH | 7.5 | 0.2% | Feb 6, 2025 | Vulnerability of incomplete verification information in the VPN service module Impact: Successful exploitation of this v... |
| CVE-2024-57961 | CRITICAL | 9.8 | 0.3% | Feb 6, 2025 | Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause fe... |
| CVE-2024-57960 | HIGH | 7.5 | 0.2% | Feb 6, 2025 | Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitation of this vulnerabi... |
| CVE-2024-57959 | CRITICAL | 9.8 | 0.2% | Feb 6, 2025 | Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause... |
| CVE-2024-57958 | CRITICAL | 9.1 | 0.2% | Feb 6, 2025 | Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may caus... |
| CVE-2024-57957 | HIGH | 7.5 | 0.3% | Feb 6, 2025 | Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vul... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now