2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43650 | CRITICAL | 9.3 | 1.6% | Jan 9, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware ... |
| CVE-2024-43649 | CRITICAL | 9.3 | 1.8% | Jan 9, 2025 | Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root u... |
| CVE-2024-43648 | CRITICAL | 9.3 | 1.8% | Jan 9, 2025 | Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root use... |
| CVE-2024-40765 | CRITICAL | 9.8 | 0.8% | Jan 9, 2025 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions ... |
| CVE-2024-12806 | MEDIUM | 4.9 | 0.6% | Jan 9, 2025 | A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an ar... |
| CVE-2024-12805 | HIGH | 7.2 | 0.7% | Jan 9, 2025 | A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and... |
| CVE-2024-12803 | HIGH | 7.2 | 0.8% | Jan 9, 2025 | A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash ... |
| CVE-2024-53706 | HIGH | 7.8 | 0.3% | Jan 9, 2025 | A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to e... |
| CVE-2024-53705 | HIGH | 7.5 | 0.7% | Jan 9, 2025 | A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establis... |
| CVE-2024-53704 | CRITICAL | 9.8 | 95.1% | Jan 9, 2025 | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe... |
| CVE-2024-40762 | CRITICAL | 9.8 | 1.0% | Jan 9, 2025 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator... |
| CVE-2024-13041 | MEDIUM | 5.4 | 0.3% | Jan 9, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 pr... |
| CVE-2024-6324 | MEDIUM | 4.3 | 0.7% | Jan 9, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 pr... |
| CVE-2024-12736 | MEDIUM | 6.1 | 0.3% | Jan 9, 2025 | The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back... |
| CVE-2024-12731 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-12717 | MEDIUM | 4.8 | 0.4% | Jan 9, 2025 | The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow... |
| CVE-2024-12715 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it b... |
| CVE-2024-12714 | MEDIUM | 6.1 | 0.4% | Jan 9, 2025 | The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-10815 | MEDIUM | 4.2 | 0.3% | Jan 9, 2025 | The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it ... |
| CVE-2024-56827 | MEDIUM | 5.6 | 0.2% | Jan 9, 2025 | A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are spe... |
| CVE-2024-56826 | MEDIUM | 5.6 | 0.3% | Jan 9, 2025 | A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are spe... |
| CVE-2024-13213 | MEDIUM | 5.4 | 0.4% | Jan 9, 2025 | A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of ... |
| CVE-2024-13212 | HIGH | 8.8 | 0.4% | Jan 9, 2025 | A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/up... |
| CVE-2024-13211 | HIGH | 8.8 | 0.4% | Jan 9, 2025 | A vulnerability was found in SingMR HouseRent 1.0. It has been rated as critical. Affected by this issue is some unknown... |
| CVE-2024-13210 | HIGH | 7.2 | 0.5% | Jan 9, 2025 | A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnera... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now