2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10239 | HIGH | 7.2 | 0.5% | Feb 4, 2025 | A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with admin... |
| CVE-2024-10238 | HIGH | 7.2 | 0.5% | Feb 4, 2025 | A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can uplo... |
| CVE-2024-10237 | HIGH | 7.2 | 0.2% | Feb 4, 2025 | There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker ... |
| CVE-2024-13607 | MEDIUM | 4.3 | 0.4% | Feb 4, 2025 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object ... |
| CVE-2024-12597 | MEDIUM | 5.4 | 0.3% | Feb 4, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'b... |
| CVE-2024-13332 | MEDIUM | 6.1 | 0.3% | Feb 4, 2025 | The TransFinanz WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2024-13331 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back... |
| CVE-2024-13330 | HIGH | 7.1 | 0.5% | Feb 4, 2025 | The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2024-13329 | HIGH | 7.1 | 0.3% | Feb 4, 2025 | The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2024-13328 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2024-13327 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the pa... |
| CVE-2024-13326 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2024-13325 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page... |
| CVE-2024-13115 | MEDIUM | 6.1 | 0.2% | Feb 4, 2025 | The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places,... |
| CVE-2024-13114 | MEDIUM | 6.1 | 0.6% | Feb 4, 2025 | The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter... |
| CVE-2024-47770 | HIGH | 8 | 0.2% | Feb 3, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin... |
| CVE-2024-35177 | HIGH | 7.8 | 0.3% | Feb 3, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin... |
| CVE-2024-57451 | HIGH | 7.5 | 0.9% | Feb 3, 2025 | ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which ... |
| CVE-2024-56903 | HIGH | 8.1 | 0.3% | Feb 3, 2025 | Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against ... |
| CVE-2024-56902 | HIGH | 7.5 | 21.3% | Feb 3, 2025 | Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which ... |
| CVE-2024-56901 | HIGH | 8.8 | 1.7% | Feb 3, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less tha... |
| CVE-2024-56898 | HIGH | 8.8 | 2.4% | Feb 3, 2025 | Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p... |
| CVE-2024-44449 | MEDIUM | 6.1 | 0.5% | Feb 3, 2025 | Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive informat... |
| CVE-2024-34897 | HIGH | 7.5 | 0.4% | Feb 3, 2025 | Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability. |
| CVE-2024-34896 | HIGH | 7.5 | 0.4% | Feb 3, 2025 | An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected f... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now