2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57618 | HIGH | 7.5 | 0.5% | Jan 14, 2025 | An issue in the bind_col_exp component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2024-57617 | HIGH | 7.5 | 0.6% | Jan 14, 2025 | An issue in the dameraulevenshtein component of MonetDB Server v11.49.1 allows attackers to cause a Denial of Service (D... |
| CVE-2024-57616 | HIGH | 7.5 | 0.6% | Jan 14, 2025 | An issue in the vscanf component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Service (DoS) via cra... |
| CVE-2024-57615 | HIGH | 7.5 | 0.6% | Jan 14, 2025 | An issue in the BATcalcbetween_intern component of MonetDB Server v11.47.11 allows attackers to cause a Denial of Servic... |
| CVE-2024-12298 | MEDIUM | 5.5 | 0.2% | Jan 14, 2025 | We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attac... |
| CVE-2024-12083 | MEDIUM | 6.6 | 0.6% | Jan 14, 2025 | Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these ... |
| CVE-2024-11396 | MEDIUM | 5.3 | 1.9% | Jan 14, 2025 | The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information ... |
| CVE-2024-57811 | CRITICAL | 9.1 | 0.4% | Jan 13, 2025 | In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH... |
| CVE-2024-56323 | CRITICAL | 9.8 | 0.4% | Jan 13, 2025 | OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19,... |
| CVE-2024-56138 | MEDIUM | 4 | 0.1% | Jan 13, 2025 | notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specificati... |
| CVE-2024-51491 | LOW | 3.3 | 0.2% | Jan 13, 2025 | notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specificati... |
| CVE-2024-11128 | HIGH | 7.8 | 0.2% | Jan 13, 2025 | A vulnerability in the BitdefenderVirusScanner binary as used in Bitdefender Virus Scanner for MacOS may allow .dynamic ... |
| CVE-2024-13324 | — | — | — | Jan 13, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: 2024-13362. Reason: This candidate is a rese... |
| CVE-2024-13154 | — | — | — | Jan 13, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: 2024-13362. Reason: This candidate is a rese... |
| CVE-2024-46481 | MEDIUM | 6.1 | 0.3% | Jan 13, 2025 | The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS. |
| CVE-2024-46480 | HIGH | 7.2 | 0.5% | Jan 13, 2025 | An NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator acc... |
| CVE-2024-46921 | MEDIUM | 6.5 | 0.3% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330,... |
| CVE-2024-46310 | CRITICAL | 9.1 | 2.4% | Jan 13, 2025 | Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary ... |
| CVE-2024-44771 | MEDIUM | 6.1 | 0.2% | Jan 13, 2025 | BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template functi... |
| CVE-2024-5743 | CRITICAL | 9.8 | 0.4% | Jan 13, 2025 | An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve... |
| CVE-2024-46920 | MEDIUM | 6.5 | 0.3% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a le... |
| CVE-2024-46479 | HIGH | 8.8 | 0.8% | Jan 13, 2025 | Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated a... |
| CVE-2024-6352 | MEDIUM | 4.3 | 0.2% | Jan 13, 2025 | A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert |
| CVE-2024-57488 | MEDIUM | 6.5 | 0.3% | Jan 13, 2025 | Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter ... |
| CVE-2024-57487 | MEDIUM | 6.5 | 2.4% | Jan 13, 2025 | In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now