2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23937 | MEDIUM | 4.3 | 0.4% | Jan 31, 2025 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sili... |
| CVE-2024-23930 | MEDIUM | 4.3 | 0.5% | Jan 31, 2025 | This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations o... |
| CVE-2024-23928 | MEDIUM | 6.5 | 0.2% | Jan 31, 2025 | This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected i... |
| CVE-2024-1211 | HIGH | 8.8 | 0.3% | Jan 31, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16... |
| CVE-2024-11611 | HIGH | 7.8 | 0.3% | Jan 30, 2025 | AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2024-11610 | HIGH | 7.8 | 0.3% | Jan 30, 2025 | AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2024-11609 | HIGH | 7.8 | 0.3% | Jan 30, 2025 | AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln... |
| CVE-2024-10604 | MEDIUM | 5.3 | 0.2% | Jan 30, 2025 | Vulnerabilities in the algorithms used by Fuchsia to populate network protocol header fields, specifically the TCP ISN, ... |
| CVE-2024-10603 | MEDIUM | 5.3 | 0.3% | Jan 30, 2025 | Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be ... |
| CVE-2024-10026 | MEDIUM | 5.3 | 0.2% | Jan 30, 2025 | A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate ... |
| CVE-2024-44142 | HIGH | 7.8 | 0.3% | Jan 30, 2025 | The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously... |
| CVE-2024-12248 | CRITICAL | 9.8 | 1.3% | Jan 30, 2025 | Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send spe... |
| CVE-2024-2658 | HIGH | 8.5 | 0.4% | Jan 30, 2025 | A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configur... |
| CVE-2024-55417 | MEDIUM | 4.3 | 12.3% | Jan 30, 2025 | DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user u... |
| CVE-2024-55416 | LOW | 3.5 | 24.1% | Jan 30, 2025 | DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticate... |
| CVE-2024-55415 | MEDIUM | 5.7 | 14.6% | Jan 30, 2025 | DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass. |
| CVE-2024-53615 | MEDIUM | 6.5 | 1.3% | Jan 30, 2025 | A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through... |
| CVE-2024-8494 | MEDIUM | 6.5 | 0.3% | Jan 30, 2025 | The Elementor Website Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u... |
| CVE-2024-13742 | CRITICAL | 9.8 | 0.9% | Jan 30, 2025 | The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versi... |
| CVE-2024-13720 | CRITICAL | 9.1 | 0.5% | Jan 30, 2025 | The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida... |
| CVE-2024-13715 | MEDIUM | 4.3 | 0.2% | Jan 30, 2025 | The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability che... |
| CVE-2024-13707 | HIGH | 8.1 | 0.2% | Jan 30, 2025 | The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2024-13705 | MEDIUM | 6.1 | 0.3% | Jan 30, 2025 | The StageShow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg wi... |
| CVE-2024-13700 | MEDIUM | 5.4 | 0.2% | Jan 30, 2025 | The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortco... |
| CVE-2024-13671 | HIGH | 7.5 | 0.5% | Jan 30, 2025 | The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now