2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52606 | CRITICAL | 9.8 | 2.3% | Feb 11, 2025 | SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied al... |
| CVE-2024-13011 | CRITICAL | 9.8 | 0.8% | Feb 10, 2025 | The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation ... |
| CVE-2024-55215 | CRITICAL | 9.8 | 1.3% | Feb 7, 2025 | An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization inter... |
| CVE-2024-57707 | CRITICAL | 9.8 | 0.7% | Feb 7, 2025 | An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components. |
| CVE-2024-36556 | CRITICAL | 9.1 | 0.3% | Feb 6, 2025 | Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R3... |
| CVE-2024-36555 | CRITICAL | 9.8 | 0.4% | Feb 6, 2025 | Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h an... |
| CVE-2024-36554 | CRITICAL | 9.8 | 0.4% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36... |
| CVE-2024-57430 | CRITICAL | 9.8 | 0.8% | Feb 6, 2025 | An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers... |
| CVE-2024-57428 | CRITICAL | 9.3 | 0.7% | Feb 6, 2025 | A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized inp... |
| CVE-2024-57961 | CRITICAL | 9.8 | 0.3% | Feb 6, 2025 | Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause fe... |
| CVE-2024-57959 | CRITICAL | 9.8 | 0.2% | Feb 6, 2025 | Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause... |
| CVE-2024-57958 | CRITICAL | 9.1 | 0.2% | Feb 6, 2025 | Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may caus... |
| CVE-2024-51547 | CRITICAL | 9.8 | 0.6% | Feb 6, 2025 | Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue aff... |
| CVE-2024-57520 | CRITICAL | 9.8 | 1.0% | Feb 5, 2025 | Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_cre... |
| CVE-2024-57077 | CRITICAL | 9.1 | 0.5% | Feb 5, 2025 | The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend... |
| CVE-2024-48445 | CRITICAL | 9.8 | 1.8% | Feb 4, 2025 | An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and t... |
| CVE-2024-9644 | CRITICAL | 9.8 | 0.6% | Feb 4, 2025 | The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the admini... |
| CVE-2024-9643 | CRITICAL | 9.8 | 3.0% | Feb 4, 2025 | The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials i... |
| CVE-2024-57450 | CRITICAL | 9.8 | 0.5% | Feb 3, 2025 | ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function. |
| CVE-2024-57099 | CRITICAL | 9.8 | 0.6% | Feb 3, 2025 | ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in ... |
| CVE-2024-57098 | CRITICAL | 9.8 | 0.4% | Feb 3, 2025 | Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into ... |
| CVE-2024-49839 | CRITICAL | 9.8 | 0.3% | Feb 3, 2025 | Memory corruption during management frame processing due to mismatch in T2LM info element. |
| CVE-2024-45569 | CRITICAL | 9.8 | 0.5% | Feb 3, 2025 | Memory corruption while parsing the ML IE due to invalid frame content. |
| CVE-2024-50500 | CRITICAL | 9.8 | 0.4% | Feb 3, 2025 | Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploi... |
| CVE-2024-57587 | CRITICAL | 9.1 | 0.5% | Jan 31, 2025 | Multiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now