2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57811 | CRITICAL | 9.1 | 0.4% | Jan 13, 2025 | In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH... |
| CVE-2024-56323 | CRITICAL | 9.8 | 0.4% | Jan 13, 2025 | OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19,... |
| CVE-2024-46310 | CRITICAL | 9.1 | 2.4% | Jan 13, 2025 | Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary ... |
| CVE-2024-5743 | CRITICAL | 9.8 | 0.4% | Jan 13, 2025 | An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve... |
| CVE-2024-42180 | CRITICAL | 9.8 | 0.2% | Jan 12, 2025 | HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, incl... |
| CVE-2024-42175 | CRITICAL | 9.8 | 0.3% | Jan 11, 2025 | HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and the... |
| CVE-2024-12877 | CRITICAL | 9.8 | 1.2% | Jan 11, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ... |
| CVE-2024-42172 | CRITICAL | 9.8 | 0.4% | Jan 11, 2025 | HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tok... |
| CVE-2024-42168 | CRITICAL | 9.4 | 0.4% | Jan 11, 2025 | HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that ... |
| CVE-2024-9132 | CRITICAL | 9.8 | 0.7% | Jan 10, 2025 | The administrator is able to configure an insecure captive portal script |
| CVE-2024-12847 | CRITICAL | 9.8 | 29.0% | Jan 10, 2025 | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated a... |
| CVE-2024-57225 | CRITICAL | 9.8 | 1.6% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the re... |
| CVE-2024-57224 | CRITICAL | 9.8 | 1.6% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc... |
| CVE-2024-57223 | CRITICAL | 9.8 | 1.6% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc... |
| CVE-2024-56511 | CRITICAL | 9.8 | 20.9% | Jan 10, 2025 | DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in t... |
| CVE-2024-29971 | CRITICAL | 9.8 | 0.4% | Jan 10, 2025 | Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals. |
| CVE-2024-29970 | CRITICAL | 9.8 | 0.4% | Jan 10, 2025 | Fortanix Enclave OS 3.36.1941-EM has an interface vulnerability that leads to state corruption via injected signals. |
| CVE-2024-57687 | CRITICAL | 9.8 | 2.6% | Jan 10, 2025 | An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v... |
| CVE-2024-57686 | CRITICAL | 9.8 | 1.6% | Jan 10, 2025 | A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record Sys... |
| CVE-2024-55225 | CRITICAL | 9.8 | 0.6% | Jan 9, 2025 | An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, inc... |
| CVE-2024-55224 | CRITICAL | 9.6 | 0.8% | Jan 9, 2025 | An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting... |
| CVE-2024-54724 | CRITICAL | 9.8 | 0.6% | Jan 9, 2025 | PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusio... |
| CVE-2024-46505 | CRITICAL | 9.1 | 0.3% | Jan 9, 2025 | Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities. |
| CVE-2024-13285 | CRITICAL | 9.8 | 0.4% | Jan 9, 2025 | Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*. |
| CVE-2024-13281 | CRITICAL | 9.1 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus:... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now