2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54999 | MEDIUM | 6.5 | 0.4% | Jan 13, 2025 | MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General ... |
| CVE-2024-48883 | MEDIUM | 4.3 | 0.2% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108... |
| CVE-2024-46919 | MEDIUM | 5.3 | 0.3% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a le... |
| CVE-2024-12211 | MEDIUM | 5.4 | 0.3% | Jan 13, 2025 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. |
| CVE-2024-52333 | HIGH | 7.8 | 0.6% | Jan 13, 2025 | An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A spe... |
| CVE-2024-47796 | HIGH | 7.8 | 0.6% | Jan 13, 2025 | An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially ... |
| CVE-2024-56301 | HIGH | 7.1 | 0.3% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in enituretechnology ... |
| CVE-2024-56065 | HIGH | 7.1 | 0.3% | Jan 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: ... |
| CVE-2024-52938 | HIGH | 7.8 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert recons... |
| CVE-2024-52937 | MEDIUM | 6.7 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou... |
| CVE-2024-52936 | MEDIUM | 4.4 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data out... |
| CVE-2024-52935 | MEDIUM | 4.1 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou... |
| CVE-2024-47897 | HIGH | 8.8 | 0.6% | Jan 13, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls resulting in platform instabil... |
| CVE-2024-47895 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outs... |
| CVE-2024-47894 | HIGH | 7.1 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outs... |
| CVE-2024-51728 | — | — | — | Jan 13, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ... |
| CVE-2024-12568 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workfl... |
| CVE-2024-12567 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form s... |
| CVE-2024-12566 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form setti... |
| CVE-2024-12274 | HIGH | 7.5 | 0.6% | Jan 13, 2025 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functional... |
| CVE-2024-11636 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text B... |
| CVE-2024-42181 | HIGH | 7.5 | 0.2% | Jan 12, 2025 | HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmit... |
| CVE-2024-42180 | CRITICAL | 9.8 | 0.2% | Jan 12, 2025 | HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, incl... |
| CVE-2024-42179 | LOW | 2.7 | 0.2% | Jan 12, 2025 | HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Micr... |
| CVE-2024-51456 | MEDIUM | 5.9 | 0.3% | Jan 12, 2025 | IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now