2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57968 | HIGH | 8.8 | 30.3% | Feb 3, 2025 | Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones... |
| CVE-2024-57669 | HIGH | 7.5 | 0.9% | Feb 3, 2025 | Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive inf... |
| CVE-2024-57498 | MEDIUM | 4.8 | 0.3% | Feb 3, 2025 | Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the... |
| CVE-2024-57452 | HIGH | 7.5 | 0.4% | Feb 3, 2025 | ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows ... |
| CVE-2024-57450 | CRITICAL | 9.8 | 0.5% | Feb 3, 2025 | ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function. |
| CVE-2024-57099 | CRITICAL | 9.8 | 0.6% | Feb 3, 2025 | ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in ... |
| CVE-2024-57098 | CRITICAL | 9.8 | 0.4% | Feb 3, 2025 | Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into ... |
| CVE-2024-57097 | MEDIUM | 4.8 | 0.2% | Feb 3, 2025 | ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php. |
| CVE-2024-56946 | MEDIUM | 5.3 | 0.4% | Feb 3, 2025 | Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the s... |
| CVE-2024-56921 | HIGH | 7.5 | 0.4% | Feb 3, 2025 | An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF ... |
| CVE-2024-12859 | HIGH | 8.8 | 0.6% | Feb 3, 2025 | The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu... |
| CVE-2024-12511 | HIGH | 7.6 | 0.6% | Feb 3, 2025 | With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This... |
| CVE-2024-11134 | MEDIUM | 6.5 | 0.3% | Feb 3, 2025 | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '... |
| CVE-2024-11133 | MEDIUM | 5.3 | 0.3% | Feb 3, 2025 | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '... |
| CVE-2024-11132 | MEDIUM | 5.4 | 0.2% | Feb 3, 2025 | The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and incl... |
| CVE-2024-57238 | HIGH | 7.3 | 0.3% | Feb 3, 2025 | Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The ... |
| CVE-2024-57237 | MEDIUM | 6.3 | 0.3% | Feb 3, 2025 | Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endp... |
| CVE-2024-57004 | MEDIUM | 6.1 | 27.8% | Feb 3, 2025 | Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malici... |
| CVE-2024-50656 | MEDIUM | 6.1 | 0.3% | Feb 3, 2025 | itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi... |
| CVE-2024-12510 | MEDIUM | 6.7 | 0.9% | Feb 3, 2025 | If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. T... |
| CVE-2024-57967 | MEDIUM | 4.2 | 0.2% | Feb 3, 2025 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated ... |
| CVE-2024-57362 | — | — | — | Feb 3, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54840. Reason: This candidate is a reservation d... |
| CVE-2024-57175 | MEDIUM | 5.4 | 0.3% | Feb 3, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 ... |
| CVE-2024-56161 | HIGH | 7.2 | 0.5% | Feb 3, 2025 | Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri... |
| CVE-2024-54840 | MEDIUM | 6.1 | 0.1% | Feb 3, 2025 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now