2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11686 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts... |
| CVE-2024-11642 | CRITICAL | 9.8 | 1.0% | Jan 9, 2025 | The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginatio... |
| CVE-2024-11328 | MEDIUM | 6.1 | 0.5% | Jan 9, 2025 | The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use ... |
| CVE-2024-13153 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widg... |
| CVE-2024-12802 | CRITICAL | 9.1 | 0.5% | Jan 9, 2025 | SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal ... |
| CVE-2024-43663 | CRITICAL | 9.8 | 1.0% | Jan 9, 2025 | There are many buffer overflow vulnerabilities present in several CGI binaries of the charging station.This issue affect... |
| CVE-2024-43662 | MEDIUM | 5.3 | 0.6% | Jan 9, 2025 | The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectiv... |
| CVE-2024-43661 | CRITICAL | 9.8 | 0.5% | Jan 9, 2025 | The <redacted>.so library, which is used by <redacted>, is vulnerable to a buffer overflow in the code that handles the ... |
| CVE-2024-43660 | HIGH | 7.5 | 0.6% | Jan 9, 2025 | The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware ... |
| CVE-2024-43659 | HIGH | 8.3 | 0.8% | Jan 9, 2025 | After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default crede... |
| CVE-2024-43658 | HIGH | 7.2 | 0.5% | Jan 9, 2025 | Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary fil... |
| CVE-2024-43657 | CRITICAL | 9.3 | 1.4% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43656 | CRITICAL | 9.3 | 1.5% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43655 | CRITICAL | 9.3 | 1.2% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43654 | CRITICAL | 9.3 | 2.1% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware... |
| CVE-2024-43653 | CRITICAL | 9.3 | 2.1% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inj... |
| CVE-2024-43652 | CRITICAL | 9.3 | 1.9% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43651 | CRITICAL | 9.3 | 1.7% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje... |
| CVE-2024-43650 | CRITICAL | 9.3 | 1.6% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware ... |
| CVE-2024-43649 | CRITICAL | 9.3 | 1.8% | Jan 9, 2025 | Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root u... |
| CVE-2024-43648 | CRITICAL | 9.3 | 1.8% | Jan 9, 2025 | Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root use... |
| CVE-2024-40765 | CRITICAL | 9.8 | 0.8% | Jan 9, 2025 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions ... |
| CVE-2024-12806 | MEDIUM | 4.9 | 0.6% | Jan 9, 2025 | A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an ar... |
| CVE-2024-12805 | HIGH | 7.2 | 0.7% | Jan 9, 2025 | A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and... |
| CVE-2024-12803 | HIGH | 7.2 | 0.8% | Jan 9, 2025 | A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now