2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13521 | MEDIUM | 5.4 | 0.1% | Jan 28, 2025 | The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2024-13509 | MEDIUM | 6.1 | 0.3% | Jan 28, 2025 | The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in al... |
| CVE-2024-13448 | CRITICAL | 9.8 | 0.9% | Jan 28, 2025 | The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2024-12807 | MEDIUM | 4.8 | 0.3% | Jan 28, 2025 | The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could... |
| CVE-2024-12723 | MEDIUM | 6.1 | 0.3% | Jan 28, 2025 | The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2024-11135 | HIGH | 7.5 | 0.4% | Jan 28, 2025 | The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees'... |
| CVE-2024-53881 | MEDIUM | 5.5 | 0.1% | Jan 28, 2025 | NVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm... |
| CVE-2024-53869 | MEDIUM | 5.5 | 0.2% | Jan 28, 2025 | NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A suc... |
| CVE-2024-0150 | HIGH | 7.1 | 0.2% | Jan 28, 2025 | NVIDIA GPU display driver for Windows and Linux contains a vulnerability where data is written past the end or before th... |
| CVE-2024-0149 | LOW | 3.3 | 0.2% | Jan 28, 2025 | NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an attacker unauthorized access to files.... |
| CVE-2024-0147 | MEDIUM | 5.5 | 0.2% | Jan 28, 2025 | NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been free... |
| CVE-2024-0146 | HIGH | 7.8 | 0.2% | Jan 28, 2025 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause memory cor... |
| CVE-2024-0140 | MEDIUM | 6.8 | 0.2% | Jan 28, 2025 | NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data is... |
| CVE-2024-0137 | MEDIUM | 6.5 | 0.3% | Jan 28, 2025 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le... |
| CVE-2024-0136 | HIGH | 8.4 | 0.7% | Jan 28, 2025 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le... |
| CVE-2024-0135 | HIGH | 7.6 | 1.1% | Jan 28, 2025 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le... |
| CVE-2024-45341 | MEDIUM | 6.1 | 0.5% | Jan 28, 2025 | A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that appl... |
| CVE-2024-45340 | HIGH | 8.8 | 0.7% | Jan 28, 2025 | Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server... |
| CVE-2024-45339 | HIGH | 7.1 | 0.3% | Jan 28, 2025 | When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged pr... |
| CVE-2024-45336 | MEDIUM | 6.1 | 0.6% | Jan 28, 2025 | The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ contai... |
| CVE-2024-22315 | MEDIUM | 6.5 | 0.2% | Jan 28, 2025 | IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker w... |
| CVE-2024-27263 | MEDIUM | 5.3 | 0.3% | Jan 28, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obt... |
| CVE-2024-12649 | CRITICAL | 9.8 | 1.2% | Jan 28, 2025 | Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow... |
| CVE-2024-12648 | CRITICAL | 9.8 | 1.2% | Jan 28, 2025 | Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may ... |
| CVE-2024-12647 | CRITICAL | 9.8 | 1.2% | Jan 28, 2025 | Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now