2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40427 | HIGH | 7.9 | 0.3% | Jan 7, 2025 | Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability... |
| CVE-2024-55414 | CRITICAL | 9.8 | 1.1% | Jan 7, 2025 | A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged u... |
| CVE-2024-55413 | HIGH | 7.8 | 0.2% | Jan 7, 2025 | A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users ... |
| CVE-2024-55412 | HIGH | 7.8 | 0.2% | Jan 7, 2025 | A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to... |
| CVE-2024-55411 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and ... |
| CVE-2024-55410 | — | — | — | Jan 7, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-54007 | HIGH | 7.2 | 1.6% | Jan 7, 2025 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead... |
| CVE-2024-54006 | HIGH | 7.2 | 1.6% | Jan 7, 2025 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead... |
| CVE-2024-50660 | CRITICAL | 9.8 | 0.9% | Jan 7, 2025 | File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload f... |
| CVE-2024-50659 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privile... |
| CVE-2024-50658 | CRITICAL | 9.8 | 0.8% | Jan 7, 2025 | Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-44450 | MEDIUM | 5.4 | 0.4% | Jan 7, 2025 | Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190. |
| CVE-2024-8361 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length tr... |
| CVE-2024-56272 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-rol... |
| CVE-2024-56270 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Retrieve Embedded Sensitive Data... |
| CVE-2024-55555 | HIGH | 8.8 | 6.5% | Jan 7, 2025 | Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_... |
| CVE-2024-40749 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | Improper Access Controls allows access to protected views. |
| CVE-2024-40748 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | Lack of output escaping in the id attribute of menu lists. |
| CVE-2024-40747 | MEDIUM | 6.1 | 0.2% | Jan 7, 2025 | Various module chromes didn't properly process inputs, leading to XSS vectors. |
| CVE-2024-12430 | HIGH | 7.3 | 0.3% | Jan 7, 2025 | An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exist... |
| CVE-2024-12429 | MEDIUM | 5.1 | 0.3% | Jan 7, 2025 | An attacker who successfully exploited these vulnerabilities could grant read access to files. A vulnerability exists in... |
| CVE-2024-56056 | HIGH | 7.1 | 0.4% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kmfoysal06 SimpleC... |
| CVE-2024-55556 | CRITICAL | 9.8 | 43.6% | Jan 7, 2025 | A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote com... |
| CVE-2024-55008 | HIGH | 7.5 | 0.8% | Jan 7, 2025 | JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent... |
| CVE-2024-53800 | HIGH | 8.1 | 0.7% | Jan 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now