2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11133 | MEDIUM | 5.3 | 0.3% | Feb 3, 2025 | The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '... |
| CVE-2024-11132 | MEDIUM | 5.4 | 0.2% | Feb 3, 2025 | The Eventer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and incl... |
| CVE-2024-57238 | HIGH | 7.3 | 0.3% | Feb 3, 2025 | Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The ... |
| CVE-2024-57237 | MEDIUM | 6.3 | 0.3% | Feb 3, 2025 | Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endp... |
| CVE-2024-57004 | MEDIUM | 6.1 | 27.8% | Feb 3, 2025 | Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malici... |
| CVE-2024-50656 | MEDIUM | 6.1 | 0.3% | Feb 3, 2025 | itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi... |
| CVE-2024-12510 | MEDIUM | 6.7 | 0.9% | Feb 3, 2025 | If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. T... |
| CVE-2024-57967 | MEDIUM | 4.2 | 0.2% | Feb 3, 2025 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated ... |
| CVE-2024-57362 | — | — | — | Feb 3, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-54840. Reason: This candidate is a reservation d... |
| CVE-2024-57175 | MEDIUM | 5.4 | 0.3% | Feb 3, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 ... |
| CVE-2024-56161 | HIGH | 7.2 | 0.5% | Feb 3, 2025 | Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri... |
| CVE-2024-54840 | MEDIUM | 6.1 | 0.1% | Feb 3, 2025 | PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address... |
| CVE-2024-53943 | MEDIUM | 6.1 | 0.3% | Feb 3, 2025 | An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln... |
| CVE-2024-53942 | MEDIUM | 4.8 | 15.2% | Feb 3, 2025 | An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vuln... |
| CVE-2024-36437 | MEDIUM | 6.5 | 0.2% | Feb 3, 2025 | The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any insta... |
| CVE-2024-55456 | MEDIUM | 6.5 | 0.4% | Feb 3, 2025 | lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell |
| CVE-2024-49843 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption while processing IOCTL from user space to handle GPU AHB bus error. |
| CVE-2024-49840 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality. |
| CVE-2024-49839 | CRITICAL | 9.8 | 0.3% | Feb 3, 2025 | Memory corruption during management frame processing due to mismatch in T2LM info element. |
| CVE-2024-49838 | HIGH | 7.5 | 0.3% | Feb 3, 2025 | Information disclosure while parsing the OCI IE with invalid length. |
| CVE-2024-49837 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption while reading CPU state data during guest VM suspend. |
| CVE-2024-49834 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption while power-up or power-down sequence of the camera sensor. |
| CVE-2024-49833 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption can occur in the camera when an invalid CID is used. |
| CVE-2024-49832 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption in Camera due to unusually high number of nodes passed to AXI port. |
| CVE-2024-45584 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption can occur when a compat IOCTL call is followed by a normal IOCTL call from userspace. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now