2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45562 | HIGH | 7.8 | 0.1% | May 6, 2025 | Memory corruption during concurrent access to server info object due to unprotected critical field. |
| CVE-2024-45554 | HIGH | 7 | 0.1% | May 6, 2025 | Memory corruption during concurrent SSR execution due to race condition on the global maps list. |
| CVE-2024-58134 | HIGH | 8.1 | 0.4% | May 3, 2025 | Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC sessio... |
| CVE-2024-13738 | HIGH | 7.3 | 0.4% | May 3, 2025 | The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-11142 | HIGH | 8.8 | 0.2% | May 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forge... |
| CVE-2024-13418 | HIGH | 8.8 | 0.6% | May 2, 2025 | Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check ... |
| CVE-2024-13344 | HIGH | 7.5 | 0.3% | May 2, 2025 | The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'pro... |
| CVE-2024-13322 | HIGH | 7.5 | 1.6% | May 2, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via... |
| CVE-2024-52903 | HIGH | 7.5 | 0.3% | May 1, 2025 | IBM Db2 for Linux, UNIX and Windows 12.1.0 and 12.1.1 is vulnerable to a denial of service as the server may crash under... |
| CVE-2024-48907 | HIGH | 7.5 | 0.4% | May 1, 2025 | Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API. |
| CVE-2024-52979 | HIGH | 7.5 | 0.5% | May 1, 2025 | Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache ... |
| CVE-2024-52976 | HIGH | 7.8 | 0.2% | May 1, 2025 | Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attacker... |
| CVE-2024-6032 | HIGH | 7.8 | 0.5% | Apr 30, 2025 | Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attack... |
| CVE-2024-6031 | HIGH | 7.8 | 0.2% | Apr 30, 2025 | Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local ... |
| CVE-2024-6030 | HIGH | 7 | 0.1% | Apr 30, 2025 | Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to es... |
| CVE-2024-13943 | HIGH | 7.8 | 0.1% | Apr 30, 2025 | Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerabil... |
| CVE-2024-9876 | HIGH | 8.5 | 0.2% | Apr 30, 2025 | : Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC... |
| CVE-2024-57698 | HIGH | 7.5 | 0.3% | Apr 29, 2025 | An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes with... |
| CVE-2024-13808 | HIGH | 8.8 | 0.6% | Apr 26, 2025 | The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i... |
| CVE-2024-6199 | HIGH | 7.7 | 0.2% | Apr 25, 2025 | An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS ... |
| CVE-2024-6198 | HIGH | 7.7 | 0.3% | Apr 25, 2025 | The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the ... |
| CVE-2024-11917 | HIGH | 8.1 | 0.4% | Apr 25, 2025 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ... |
| CVE-2024-33452 | HIGH | 7.7 | 0.7% | Apr 22, 2025 | An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling v... |
| CVE-2024-46546 | HIGH | 7.3 | 0.4% | Apr 22, 2025 | NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formF... |
| CVE-2024-40445 | HIGH | 7.3 | 0.6% | Apr 22, 2025 | A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now