2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35276 | CRITICAL | 9.8 | 0.4% | Jan 14, 2025 | A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7... |
| CVE-2024-35275 | HIGH | 8.8 | 0.8% | Jan 14, 2025 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version... |
| CVE-2024-35273 | HIGH | 8.8 | 0.6% | Jan 14, 2025 | A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 al... |
| CVE-2024-33503 | HIGH | 7.8 | 0.2% | Jan 14, 2025 | A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2... |
| CVE-2024-33502 | HIGH | 7.2 | 1.2% | Jan 14, 2025 | An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyze... |
| CVE-2024-32115 | MEDIUM | 5.5 | 1.0% | Jan 14, 2025 | A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 ... |
| CVE-2024-27778 | HIGH | 8.8 | 0.5% | Jan 14, 2025 | An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo... |
| CVE-2024-26012 | HIGH | 7.8 | 0.7% | Jan 14, 2025 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 a... |
| CVE-2024-23106 | CRITICAL | 9.8 | 0.9% | Jan 14, 2025 | An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and... |
| CVE-2024-21758 | MEDIUM | 6.7 | 0.2% | Jan 14, 2025 | A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a pri... |
| CVE-2024-11864 | HIGH | 7.5 | 0.5% | Jan 14, 2025 | Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may l... |
| CVE-2024-11863 | MEDIUM | 5.3 | 0.4% | Jan 14, 2025 | Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may l... |
| CVE-2024-11497 | HIGH | 8.8 | 0.4% | Jan 14, 2025 | An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access. |
| CVE-2024-56841 | CRITICAL | 9.1 | 0.5% | Jan 14, 2025 | A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerab... |
| CVE-2024-53649 | HIGH | 7.1 | 0.6% | Jan 14, 2025 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.80), SIPROTEC 5 6MD85 (CP300) (All ve... |
| CVE-2024-47100 | HIGH | 7.2 | 0.2% | Jan 14, 2025 | A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 121... |
| CVE-2024-45385 | MEDIUM | 6.1 | 0.3% | Jan 14, 2025 | A vulnerability has been identified in Industrial Edge Management OS (IEM-OS) (All versions). Affected components are vu... |
| CVE-2024-12240 | MEDIUM | 5.4 | 0.3% | Jan 14, 2025 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label param... |
| CVE-2024-12919 | CRITICAL | 9.8 | 0.5% | Jan 14, 2025 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres... |
| CVE-2024-13156 | MEDIUM | 6.4 | 0.3% | Jan 14, 2025 | The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-... |
| CVE-2024-11736 | MEDIUM | 4.9 | 0.8% | Jan 14, 2025 | A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system ... |
| CVE-2024-11734 | MEDIUM | 6.5 | 0.9% | Jan 14, 2025 | A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change... |
| CVE-2024-12365 | HIGH | 8.5 | 1.7% | Jan 14, 2025 | The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o... |
| CVE-2024-12008 | HIGH | 7.5 | 2.2% | Jan 14, 2025 | The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.... |
| CVE-2024-12006 | MEDIUM | 5.3 | 0.5% | Jan 14, 2025 | The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now