2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55573 | HIGH | 7.2 | 1.1% | Jan 23, 2025 | An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19... |
| CVE-2024-53379 | HIGH | 7.5 | 0.5% | Jan 23, 2025 | Heap buffer overflow in the server site handshake implementation in Real Time Logic LLC's SharkSSL version (from 05/05/2... |
| CVE-2024-57556 | MEDIUM | 6.1 | 0.3% | Jan 23, 2025 | Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary cod... |
| CVE-2024-57386 | MEDIUM | 6.1 | 0.4% | Jan 23, 2025 | Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile... |
| CVE-2024-57329 | MEDIUM | 5.4 | 0.3% | Jan 23, 2025 | HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize o... |
| CVE-2024-57328 | CRITICAL | 9.8 | 0.5% | Jan 23, 2025 | A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises bec... |
| CVE-2024-57326 | MEDIUM | 6.1 | 0.3% | Jan 23, 2025 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1... |
| CVE-2024-55195 | HIGH | 7.5 | 0.5% | Jan 23, 2025 | An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.1.0.0dev may cause a Denial of Service (... |
| CVE-2024-55194 | CRITICAL | 9.8 | 0.7% | Jan 23, 2025 | OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h. |
| CVE-2024-55193 | CRITICAL | 9.8 | 0.5% | Jan 23, 2025 | OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h. |
| CVE-2024-55192 | CRITICAL | 9.8 | 0.6% | Jan 23, 2025 | OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inline... |
| CVE-2024-53923 | HIGH | 7.2 | 0.4% | Jan 23, 2025 | An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x... |
| CVE-2024-53588 | HIGH | 7.8 | 0.2% | Jan 23, 2025 | A DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL fil... |
| CVE-2024-50665 | MEDIUM | 5.5 | 0.2% | Jan 23, 2025 | gpac 2.4 contains a SEGV at src/isomedia/drm_sample.c:1562:96 in isom_cenc_get_sai_by_saiz_saio in MP4Box. |
| CVE-2024-50664 | HIGH | 7.8 | 0.3% | Jan 23, 2025 | gpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box. |
| CVE-2024-55930 | CRITICAL | 9.8 | 0.3% | Jan 23, 2025 | Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete fil... |
| CVE-2024-55929 | MEDIUM | 5.3 | 0.2% | Jan 23, 2025 | A mail spoofing vulnerability in Xerox Workplace Suite allows attackers to forge email headers, making it appear as thou... |
| CVE-2024-55928 | HIGH | 7.5 | 0.1% | Jan 23, 2025 | Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows atta... |
| CVE-2024-55927 | HIGH | 7.5 | 0.3% | Jan 23, 2025 | A vulnerability in Xerox Workplace Suite arises from flawed token generation and the use of hard-coded keys. These weakn... |
| CVE-2024-55926 | CRITICAL | 9.8 | 0.4% | Jan 23, 2025 | A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through cr... |
| CVE-2024-45672 | MEDIUM | 6 | 0.1% | Jan 23, 2025 | IBM Security Verify Bridge 1.0.0 through 1.0.15 could allow a local privileged user to overwrite files due to excessive ... |
| CVE-2024-55925 | HIGH | 7.5 | 0.4% | Jan 23, 2025 | In Xerox Workplace Suite, an API restricted to specific hosts can be bypassed by manipulating the Host header. If the se... |
| CVE-2024-52331 | HIGH | 7.7 | 0.2% | Jan 23, 2025 | ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can crea... |
| CVE-2024-52330 | CRITICAL | 9.5 | 0.3% | Jan 23, 2025 | ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify... |
| CVE-2024-52329 | HIGH | 7.4 | 0.4% | Jan 23, 2025 | ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attack... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now