2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55062 | CRITICAL | 9.8 | 1.0% | Jan 31, 2025 | Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers ... |
| CVE-2024-53356 | CRITICAL | 9.8 | 0.6% | Jan 31, 2025 | Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JW... |
| CVE-2024-53584 | CRITICAL | 9.8 | 4.4% | Jan 31, 2025 | OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter. |
| CVE-2024-47857 | CRITICAL | 9.8 | 0.4% | Jan 31, 2025 | SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures w... |
| CVE-2024-53537 | CRITICAL | 9.1 | 2.2% | Jan 31, 2025 | An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager... |
| CVE-2024-53320 | CRITICAL | 9.8 | 0.4% | Jan 31, 2025 | Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveC... |
| CVE-2024-12267 | CRITICAL | 9.1 | 0.3% | Jan 31, 2025 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file del... |
| CVE-2024-12248 | CRITICAL | 9.8 | 1.3% | Jan 30, 2025 | Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send spe... |
| CVE-2024-13742 | CRITICAL | 9.8 | 0.9% | Jan 30, 2025 | The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versi... |
| CVE-2024-13720 | CRITICAL | 9.1 | 0.5% | Jan 30, 2025 | The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida... |
| CVE-2024-12822 | CRITICAL | 9.8 | 0.6% | Jan 30, 2025 | The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p... |
| CVE-2024-57665 | CRITICAL | 9.8 | 0.5% | Jan 29, 2025 | JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability... |
| CVE-2024-57395 | CRITICAL | 9.8 | 0.7% | Jan 29, 2025 | Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileg... |
| CVE-2024-54852 | CRITICAL | 9.8 | 0.7% | Jan 29, 2025 | When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnera... |
| CVE-2024-48852 | CRITICAL | 9.4 | 2.4% | Jan 29, 2025 | Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly di... |
| CVE-2024-48849 | CRITICAL | 9.4 | 0.9% | Jan 29, 2025 | Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauth... |
| CVE-2024-57965 | CRITICAL | 9.8 | 0.4% | Jan 29, 2025 | In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a po... |
| CVE-2024-13448 | CRITICAL | 9.8 | 0.9% | Jan 28, 2025 | The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2024-12649 | CRITICAL | 9.8 | 1.2% | Jan 28, 2025 | Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow... |
| CVE-2024-12648 | CRITICAL | 9.8 | 1.2% | Jan 28, 2025 | Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may ... |
| CVE-2024-12647 | CRITICAL | 9.8 | 1.2% | Jan 28, 2025 | Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may ... |
| CVE-2024-57548 | CRITICAL | 9.1 | 0.5% | Jan 27, 2025 | CMSimple 5.16 allows the user to edit log.php file via print page. |
| CVE-2024-57052 | CRITICAL | 9.8 | 0.5% | Jan 27, 2025 | An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter i... |
| CVE-2024-54542 | CRITICAL | 9.1 | 0.7% | Jan 27, 2025 | An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and i... |
| CVE-2024-54530 | CRITICAL | 9.1 | 0.6% | Jan 27, 2025 | The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now