2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56771 | MEDIUM | 5.5 | 0.2% | Jan 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: mtd: spinand: winbond: Fix 512GW, 01GW, 01JW and 02... |
| CVE-2024-51442 | HIGH | 8.8 | 2.2% | Jan 8, 2025 | Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specia... |
| CVE-2024-56770 | MEDIUM | 5.5 | 0.3% | Jan 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/sched: netem: account for backlog updates from ... |
| CVE-2024-55459 | MEDIUM | 6.5 | 0.2% | Jan 8, 2025 | An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar fi... |
| CVE-2024-13187 | MEDIUM | 5.3 | 0.2% | Jan 8, 2025 | A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vul... |
| CVE-2024-55656 | HIGH | 8.8 | 15.0% | Jan 8, 2025 | RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloo... |
| CVE-2024-55517 | HIGH | 8.8 | 0.5% | Jan 8, 2025 | An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the... |
| CVE-2024-51737 | HIGH | 7 | 0.4% | Jan 8, 2025 | RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticate... |
| CVE-2024-51480 | HIGH | 7 | 0.2% | Jan 8, 2025 | RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYIND... |
| CVE-2024-12337 | MEDIUM | 6.1 | 0.3% | Jan 8, 2025 | The Shipping via Planzer for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘p... |
| CVE-2024-11830 | MEDIUM | 6.4 | 0.3% | Jan 8, 2025 | The PDF Flipbook, 3D Flipbook—DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline set... |
| CVE-2024-11423 | HIGH | 7.5 | 0.8% | Jan 8, 2025 | The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Cou... |
| CVE-2024-12854 | HIGH | 8.8 | 0.8% | Jan 8, 2025 | The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio... |
| CVE-2024-12853 | HIGH | 8.8 | 0.8% | Jan 8, 2025 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio... |
| CVE-2024-12712 | MEDIUM | 5.3 | 0.3% | Jan 8, 2025 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-9939 | HIGH | 7.5 | 1.0% | Jan 8, 2025 | The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2... |
| CVE-2024-54676 | CRITICAL | 9.8 | 65.2% | Jan 8, 2025 | Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Def... |
| CVE-2024-45033 | HIGH | 8.1 | 0.9% | Jan 8, 2025 | Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Pro... |
| CVE-2024-13186 | HIGH | 7.5 | 0.3% | Jan 8, 2025 | The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. |
| CVE-2024-13185 | HIGH | 7.5 | 0.3% | Jan 8, 2025 | The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. |
| CVE-2024-12855 | MEDIUM | 5.4 | 0.3% | Jan 8, 2025 | The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2024-12328 | MEDIUM | 6.4 | 0.3% | Jan 8, 2025 | The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions... |
| CVE-2024-11939 | HIGH | 7.5 | 0.4% | Jan 8, 2025 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ para... |
| CVE-2024-11350 | CRITICAL | 9.8 | 0.7% | Jan 8, 2025 | The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i... |
| CVE-2024-13173 | HIGH | 7.5 | 0.3% | Jan 8, 2025 | The health module has insufficient restrictions on loading URLs, which may lead to some information leakage. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now