2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4227 | HIGH | 7.5 | 0.7% | Jan 15, 2025 | In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forc... |
| CVE-2024-11870 | MEDIUM | 6.4 | 0.3% | Jan 15, 2025 | The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-55577 | HIGH | 7 | 0.3% | Jan 15, 2025 | Stack-based buffer overflow vulnerability exists in Linux Ratfor 1.06 and earlier. When the software processes a file wh... |
| CVE-2024-13394 | MEDIUM | 6.4 | 0.4% | Jan 15, 2025 | The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortco... |
| CVE-2024-13334 | MEDIUM | 6.1 | 0.3% | Jan 15, 2025 | The Car Demon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_condition' parameter ... |
| CVE-2024-57767 | HIGH | 8.6 | 0.4% | Jan 15, 2025 | MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download. |
| CVE-2024-57766 | CRITICAL | 9.1 | 0.5% | Jan 15, 2025 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table... |
| CVE-2024-57765 | HIGH | 7.5 | 0.4% | Jan 15, 2025 | MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list. |
| CVE-2024-57764 | CRITICAL | 9.1 | 0.5% | Jan 15, 2025 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table... |
| CVE-2024-57763 | CRITICAL | 9.1 | 0.5% | Jan 15, 2025 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table... |
| CVE-2024-57762 | HIGH | 7.5 | 0.5% | Jan 15, 2025 | MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file. |
| CVE-2024-57761 | HIGH | 8.1 | 0.5% | Jan 15, 2025 | An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execut... |
| CVE-2024-57760 | MEDIUM | 6.5 | 0.4% | Jan 15, 2025 | JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CG... |
| CVE-2024-57757 | HIGH | 7.5 | 0.4% | Jan 15, 2025 | JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.c... |
| CVE-2024-57483 | CRITICAL | 9.8 | 0.6% | Jan 14, 2025 | Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function. |
| CVE-2024-57473 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address edit... |
| CVE-2024-54730 | HIGH | 7.5 | 0.5% | Jan 14, 2025 | Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function. |
| CVE-2024-54142 | CRITICAL | 9 | 0.4% | Jan 14, 2025 | Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations i... |
| CVE-2024-53277 | MEDIUM | 5.4 | 0.3% | Jan 14, 2025 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HT... |
| CVE-2024-47605 | MEDIUM | 5.4 | 1.1% | Jan 14, 2025 | silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functional... |
| CVE-2024-42911 | HIGH | 7.4 | 0.6% | Jan 14, 2025 | ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vuln... |
| CVE-2024-57482 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless netw... |
| CVE-2024-57480 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration... |
| CVE-2024-57479 | CRITICAL | 9.8 | 0.6% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address upda... |
| CVE-2024-57471 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless ne... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now