2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49748 | CRITICAL | 9.8 | 0.4% | Jan 21, 2025 | In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflo... |
| CVE-2024-49747 | CRITICAL | 9.8 | 0.5% | Jan 21, 2025 | In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the cod... |
| CVE-2024-24421 | CRITICAL | 9.8 | 0.9% | Jan 21, 2025 | A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa... |
| CVE-2024-45479 | CRITICAL | 9.1 | 0.6% | Jan 21, 2025 | SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upg... |
| CVE-2024-55959 | CRITICAL | 9.1 | 0.8% | Jan 21, 2025 | Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions. |
| CVE-2024-42936 | CRITICAL | 9.8 | 1.0% | Jan 21, 2025 | The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Ex... |
| CVE-2024-54794 | CRITICAL | 9.1 | 12.7% | Jan 21, 2025 | The script input feature of SpagoBI 3.5.1 allows arbitrary code execution. |
| CVE-2024-51919 | CRITICAL | 9 | 0.5% | Jan 21, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.T... |
| CVE-2024-51888 | CRITICAL | 9.8 | 0.4% | Jan 21, 2025 | Incorrect Privilege Assignment vulnerability in favethemes Homey Login Register homey-login-register allows Privilege Es... |
| CVE-2024-51818 | CRITICAL | 9.3 | 15.5% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Prod... |
| CVE-2024-49688 | CRITICAL | 9.8 | 0.4% | Jan 21, 2025 | Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue ... |
| CVE-2024-49655 | CRITICAL | 9.3 | 0.3% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ... |
| CVE-2024-32555 | CRITICAL | 9.8 | 0.5% | Jan 21, 2025 | Incorrect Privilege Assignment vulnerability in InspiryThemes Easy Real Estate easy-real-estate allows Privilege Escalat... |
| CVE-2024-45647 | CRITICAL | 9.8 | 0.3% | Jan 20, 2025 | IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow... |
| CVE-2024-41783 | CRITICAL | 9.1 | 0.6% | Jan 19, 2025 | IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inje... |
| CVE-2024-38337 | CRITICAL | 9.1 | 0.5% | Jan 19, 2025 | IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker ... |
| CVE-2024-47113 | CRITICAL | 9.1 | 0.6% | Jan 18, 2025 | IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacke... |
| CVE-2024-13375 | CRITICAL | 9.8 | 1.4% | Jan 18, 2025 | The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to... |
| CVE-2024-57035 | CRITICAL | 9.8 | 0.5% | Jan 17, 2025 | WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php. |
| CVE-2024-57034 | CRITICAL | 9.8 | 0.6% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter. |
| CVE-2024-57032 | CRITICAL | 9.8 | 0.6% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the v... |
| CVE-2024-57031 | CRITICAL | 9.8 | 0.6% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter. |
| CVE-2024-13503 | CRITICAL | 9.5 | 0.5% | Jan 17, 2025 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299... |
| CVE-2024-13502 | CRITICAL | 9.3 | 0.6% | Jan 17, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDire... |
| CVE-2024-57703 | CRITICAL | 9.8 | 0.5% | Jan 16, 2025 | Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now