2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57764 | CRITICAL | 9.1 | 0.5% | Jan 15, 2025 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table... |
| CVE-2024-57763 | CRITICAL | 9.1 | 0.5% | Jan 15, 2025 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table... |
| CVE-2024-57762 | HIGH | 7.5 | 0.5% | Jan 15, 2025 | MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file. |
| CVE-2024-57761 | HIGH | 8.1 | 0.5% | Jan 15, 2025 | An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execut... |
| CVE-2024-57760 | MEDIUM | 6.5 | 0.4% | Jan 15, 2025 | JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CG... |
| CVE-2024-57757 | HIGH | 7.5 | 0.4% | Jan 15, 2025 | JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.c... |
| CVE-2024-57483 | CRITICAL | 9.8 | 0.6% | Jan 14, 2025 | Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function. |
| CVE-2024-57473 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address edit... |
| CVE-2024-54730 | HIGH | 7.5 | 0.5% | Jan 14, 2025 | Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function. |
| CVE-2024-54142 | CRITICAL | 9 | 0.4% | Jan 14, 2025 | Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations i... |
| CVE-2024-53277 | MEDIUM | 5.4 | 0.3% | Jan 14, 2025 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HT... |
| CVE-2024-47605 | MEDIUM | 5.4 | 1.1% | Jan 14, 2025 | silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functional... |
| CVE-2024-42911 | HIGH | 7.4 | 0.6% | Jan 14, 2025 | ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vuln... |
| CVE-2024-57482 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless netw... |
| CVE-2024-57480 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration... |
| CVE-2024-57479 | CRITICAL | 9.8 | 0.6% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address upda... |
| CVE-2024-57471 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless ne... |
| CVE-2024-50861 | MEDIUM | 6.1 | 0.8% | Jan 14, 2025 | The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious cod... |
| CVE-2024-50859 | MEDIUM | 4.8 | 0.8% | Jan 14, 2025 | The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly forma... |
| CVE-2024-50858 | HIGH | 8.8 | 1.7% | Jan 14, 2025 | Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actio... |
| CVE-2024-50857 | MEDIUM | 4.8 | 1.2% | Jan 14, 2025 | The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and en... |
| CVE-2024-48760 | CRITICAL | 9.8 | 45.1% | Jan 14, 2025 | An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke... |
| CVE-2024-45102 | MEDIUM | 6.8 | 0.2% | Jan 14, 2025 | A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their ... |
| CVE-2024-10254 | MEDIUM | 4.7 | 0.1% | Jan 14, 2025 | A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could al... |
| CVE-2024-10253 | MEDIUM | 4.7 | 0.1% | Jan 14, 2025 | A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a loc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now