2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12085 | HIGH | 7.5 | 8.8% | Jan 14, 2025 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to m... |
| CVE-2024-53563 | MEDIUM | 5.4 | 0.2% | Jan 14, 2025 | A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to ex... |
| CVE-2024-53561 | HIGH | 8.7 | 0.6% | Jan 14, 2025 | A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute ... |
| CVE-2024-52898 | MEDIUM | 6.2 | 0.2% | Jan 14, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a ... |
| CVE-2024-45627 | MEDIUM | 5.9 | 0.3% | Jan 14, 2025 | In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql J... |
| CVE-2024-13181 | CRITICAL | 9.8 | 32.4% | Jan 14, 2025 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authenticatio... |
| CVE-2024-13180 | HIGH | 7.5 | 27.8% | Jan 14, 2025 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive infor... |
| CVE-2024-13179 | CRITICAL | 9.8 | 61.8% | Jan 14, 2025 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authenticatio... |
| CVE-2024-10811 | HIGH | 7.5 | 3.2% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-10630 | HIGH | 7 | 0.2% | Jan 14, 2025 | A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to ... |
| CVE-2024-29980 | LOW | 3.3 | 0.1% | Jan 14, 2025 | Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix S... |
| CVE-2024-29979 | LOW | 3.3 | 0.2% | Jan 14, 2025 | Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore™ for Intel Kaby Lake, Phoenix S... |
| CVE-2024-55000 | MEDIUM | 5.4 | 0.3% | Jan 14, 2025 | Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categori... |
| CVE-2024-42444 | HIGH | 7.8 | 0.1% | Jan 14, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful e... |
| CVE-2024-39803 | HIGH | 7.2 | 1.2% | Jan 14, 2025 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030... |
| CVE-2024-39802 | HIGH | 7.2 | 0.8% | Jan 14, 2025 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030... |
| CVE-2024-39801 | HIGH | 7.2 | 1.3% | Jan 14, 2025 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030... |
| CVE-2024-39800 | HIGH | 7.2 | 1.8% | Jan 14, 2025 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli... |
| CVE-2024-39799 | HIGH | 7.2 | 1.3% | Jan 14, 2025 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli... |
| CVE-2024-39798 | HIGH | 7.2 | 1.8% | Jan 14, 2025 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli... |
| CVE-2024-39795 | HIGH | 7.2 | 1.5% | Jan 14, 2025 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 ... |
| CVE-2024-39794 | HIGH | 7.2 | 1.0% | Jan 14, 2025 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 ... |
| CVE-2024-39793 | HIGH | 7.2 | 1.5% | Jan 14, 2025 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 ... |
| CVE-2024-39790 | HIGH | 7.2 | 1.5% | Jan 14, 2025 | Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A... |
| CVE-2024-39789 | HIGH | 7.2 | 1.0% | Jan 14, 2025 | Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now