2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54530 | CRITICAL | 9.1 | 0.6% | Jan 27, 2025 | The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visio... |
| CVE-2024-54512 | CRITICAL | 9.1 | 0.4% | Jan 27, 2025 | The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 18.2, watchOS 11.2. A... |
| CVE-2024-48841 | CRITICAL | 10 | 4.3% | Jan 27, 2025 | Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and... |
| CVE-2024-55228 | CRITICAL | 9 | 0.6% | Jan 27, 2025 | A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute ar... |
| CVE-2024-55227 | CRITICAL | 9 | 0.6% | Jan 27, 2025 | A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to exec... |
| CVE-2024-57595 | CRITICAL | 9.8 | 1.1% | Jan 27, 2025 | DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, whic... |
| CVE-2024-57590 | CRITICAL | 9.8 | 1.1% | Jan 27, 2025 | TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",whi... |
| CVE-2024-50698 | CRITICAL | 9.8 | 0.6% | Jan 24, 2025 | SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of... |
| CVE-2024-50695 | CRITICAL | 9.8 | 0.6% | Jan 24, 2025 | SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT mess... |
| CVE-2024-50694 | CRITICAL | 9.8 | 0.6% | Jan 24, 2025 | In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the under... |
| CVE-2024-56404 | CRITICAL | 9.9 | 0.6% | Jan 24, 2025 | In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privile... |
| CVE-2024-13545 | CRITICAL | 9.8 | 1.3% | Jan 24, 2025 | The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1... |
| CVE-2024-57328 | CRITICAL | 9.8 | 0.5% | Jan 23, 2025 | A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises bec... |
| CVE-2024-55194 | CRITICAL | 9.8 | 0.7% | Jan 23, 2025 | OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h. |
| CVE-2024-55193 | CRITICAL | 9.8 | 0.5% | Jan 23, 2025 | OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h. |
| CVE-2024-55192 | CRITICAL | 9.8 | 0.6% | Jan 23, 2025 | OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inline... |
| CVE-2024-55930 | CRITICAL | 9.8 | 0.3% | Jan 23, 2025 | Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete fil... |
| CVE-2024-55926 | CRITICAL | 9.8 | 0.4% | Jan 23, 2025 | A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through cr... |
| CVE-2024-52330 | CRITICAL | 9.5 | 0.3% | Jan 23, 2025 | ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify... |
| CVE-2024-55971 | CRITICAL | 10 | 0.6% | Jan 23, 2025 | SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauth... |
| CVE-2024-52325 | CRITICAL | 9.6 | 3.0% | Jan 23, 2025 | ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE con... |
| CVE-2024-13234 | CRITICAL | 9.8 | 0.5% | Jan 23, 2025 | The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in ... |
| CVE-2024-52975 | CRITICAL | 9 | 0.3% | Jan 23, 2025 | An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INF... |
| CVE-2024-12857 | CRITICAL | 9.8 | 0.7% | Jan 22, 2025 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. Thi... |
| CVE-2024-13091 | CRITICAL | 9.8 | 0.8% | Jan 22, 2025 | The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now