2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6030 | HIGH | 7 | 0.1% | Apr 30, 2025 | Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to es... |
| CVE-2024-13943 | HIGH | 7.8 | 0.1% | Apr 30, 2025 | Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerabil... |
| CVE-2024-9876 | HIGH | 8.5 | 0.2% | Apr 30, 2025 | : Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC... |
| CVE-2024-57698 | HIGH | 7.5 | 0.3% | Apr 29, 2025 | An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes with... |
| CVE-2024-13808 | HIGH | 8.8 | 0.6% | Apr 26, 2025 | The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i... |
| CVE-2024-6199 | HIGH | 7.7 | 0.2% | Apr 25, 2025 | An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS ... |
| CVE-2024-6198 | HIGH | 7.7 | 0.3% | Apr 25, 2025 | The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the ... |
| CVE-2024-11917 | HIGH | 8.1 | 0.4% | Apr 25, 2025 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ... |
| CVE-2024-33452 | HIGH | 7.7 | 0.7% | Apr 22, 2025 | An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling v... |
| CVE-2024-46546 | HIGH | 7.3 | 0.4% | Apr 22, 2025 | NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formF... |
| CVE-2024-40445 | HIGH | 7.3 | 0.6% | Apr 22, 2025 | A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read ... |
| CVE-2024-11299 | HIGH | 7.5 | 0.3% | Apr 22, 2025 | The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2024-13569 | HIGH | 7.1 | 0.5% | Apr 22, 2025 | The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-46899 | HIGH | 7.1 | 0.3% | Apr 22, 2025 | Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentia... |
| CVE-2024-57394 | HIGH | 8.8 | 0.5% | Apr 21, 2025 | The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore ... |
| CVE-2024-13926 | HIGH | 7.5 | 0.4% | Apr 19, 2025 | The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post contain... |
| CVE-2024-42178 | HIGH | 7.5 | 0.2% | Apr 17, 2025 | HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthori... |
| CVE-2024-55211 | HIGH | 8.4 | 0.2% | Apr 17, 2025 | An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie. |
| CVE-2024-55238 | HIGH | 8.8 | 0.5% | Apr 17, 2025 | OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function l... |
| CVE-2024-12530 | HIGH | 7 | 0.2% | Apr 17, 2025 | Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.Thi... |
| CVE-2024-13925 | HIGH | 7.5 | 0.4% | Apr 17, 2025 | The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint ... |
| CVE-2024-53305 | HIGH | 7.3 | 0.5% | Apr 16, 2025 | An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supp... |
| CVE-2024-53303 | HIGH | 8.8 | 0.7% | Apr 16, 2025 | A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 al... |
| CVE-2024-22314 | HIGH | 7.5 | 0.2% | Apr 16, 2025 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that c... |
| CVE-2024-58093 | HIGH | 7.8 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstrea... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now