2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57276 | HIGH | 7.3 | 0.2% | Jan 27, 2025 | In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. Th... |
| CVE-2024-57272 | MEDIUM | 6.1 | 0.2% | Jan 27, 2025 | SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower is vulnerable to Cross Site Scripting (XSS). |
| CVE-2024-55228 | CRITICAL | 9 | 0.6% | Jan 27, 2025 | A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute ar... |
| CVE-2024-55227 | CRITICAL | 9 | 0.6% | Jan 27, 2025 | A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to exec... |
| CVE-2024-54146 | HIGH | 8.8 | 38.6% | Jan 27, 2025 | Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the templ... |
| CVE-2024-54145 | HIGH | 8.8 | 0.7% | Jan 27, 2025 | Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the get_d... |
| CVE-2024-48420 | HIGH | 8.8 | 0.5% | Jan 27, 2025 | Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/getWifiBasic. |
| CVE-2024-48419 | HIGH | 8.8 | 2.1% | Jan 27, 2025 | Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specificall... |
| CVE-2024-48418 | HIGH | 8.8 | 0.3% | Jan 27, 2025 | In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle speci... |
| CVE-2024-48417 | MEDIUM | 5.2 | 0.3% | Jan 27, 2025 | Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Cross Site Scripting (XSS) in : /bin/goahead via ... |
| CVE-2024-48416 | HIGH | 8.8 | 0.5% | Jan 27, 2025 | Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClient... |
| CVE-2024-27256 | HIGH | 7.5 | 0.2% | Jan 27, 2025 | IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 LTS and 2.4.0 through 2.4.8, 2.3.0 throu... |
| CVE-2024-45598 | MEDIUM | 4.9 | 2.9% | Jan 27, 2025 | Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Po... |
| CVE-2024-38325 | HIGH | 7.5 | 0.2% | Jan 27, 2025 | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI could allow a remote attacker to obtain sensi... |
| CVE-2024-38320 | HIGH | 7.5 | 0.2% | Jan 27, 2025 | IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0... |
| CVE-2024-37527 | MEDIUM | 5.4 | 0.2% | Jan 27, 2025 | IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated ... |
| CVE-2024-22316 | MEDIUM | 4.3 | 0.2% | Jan 27, 2025 | IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perfo... |
| CVE-2024-57595 | CRITICAL | 9.8 | 1.1% | Jan 27, 2025 | DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, whic... |
| CVE-2024-57590 | CRITICAL | 9.8 | 1.1% | Jan 27, 2025 | TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",whi... |
| CVE-2024-11348 | MEDIUM | 5.3 | 0.4% | Jan 27, 2025 | Eura7 CMSmanager in version 4.6 and below is vulnerable to Reflected XSS attacks through manipulation of return GET requ... |
| CVE-2024-55931 | MEDIUM | 6.5 | 0.3% | Jan 27, 2025 | Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is... |
| CVE-2024-12345 | MEDIUM | 6.7 | 0.2% | Jan 27, 2025 | A vulnerability classified as problematic was found in INW Krbyyyzo 25.2002. Affected by this vulnerability is an unknow... |
| CVE-2024-52012 | MEDIUM | 5.4 | 43.3% | Jan 27, 2025 | Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary fil... |
| CVE-2024-43446 | LOW | 3.5 | 0.2% | Jan 27, 2025 | An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even ... |
| CVE-2024-43445 | MEDIUM | 5.4 | 0.2% | Jan 27, 2025 | A vulnerability exists in OTRS and ((OTRS Community Edition)) that fail to set the HTTP response header X-Content-Type-O... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now