2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50603 | CRITICAL | 9.8 | 98.5% | Jan 8, 2025 | An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza... |
| CVE-2024-40679 | MEDIUM | 5.5 | 0.2% | Jan 8, 2025 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulner... |
| CVE-2024-10541 | — | — | — | Jan 7, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. This is not ... |
| CVE-2024-55218 | MEDIUM | 6.1 | 0.7% | Jan 7, 2025 | IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter. |
| CVE-2024-54819 | CRITICAL | 9.1 | 18.2% | Jan 7, 2025 | I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input valid... |
| CVE-2024-53522 | HIGH | 7.5 | 0.8% | Jan 7, 2025 | Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe ... |
| CVE-2024-35532 | CRITICAL | 9.1 | 0.5% | Jan 7, 2025 | An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attacke... |
| CVE-2024-40427 | HIGH | 7.9 | 0.3% | Jan 7, 2025 | Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability... |
| CVE-2024-55414 | CRITICAL | 9.8 | 1.1% | Jan 7, 2025 | A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged u... |
| CVE-2024-55413 | HIGH | 7.8 | 0.2% | Jan 7, 2025 | A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users ... |
| CVE-2024-55412 | HIGH | 7.8 | 0.2% | Jan 7, 2025 | A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to... |
| CVE-2024-55411 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and ... |
| CVE-2024-55410 | — | — | — | Jan 7, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-54007 | HIGH | 7.2 | 1.6% | Jan 7, 2025 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead... |
| CVE-2024-54006 | HIGH | 7.2 | 1.6% | Jan 7, 2025 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead... |
| CVE-2024-50660 | CRITICAL | 9.8 | 0.9% | Jan 7, 2025 | File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload f... |
| CVE-2024-50659 | MEDIUM | 6.1 | 0.3% | Jan 7, 2025 | Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privile... |
| CVE-2024-50658 | CRITICAL | 9.8 | 0.8% | Jan 7, 2025 | Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-44450 | MEDIUM | 5.4 | 0.4% | Jan 7, 2025 | Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190. |
| CVE-2024-8361 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length tr... |
| CVE-2024-56272 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-rol... |
| CVE-2024-56270 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | Missing Authorization vulnerability in SecureSubmit WP SecureSubmit securesubmit allows Retrieve Embedded Sensitive Data... |
| CVE-2024-55555 | HIGH | 8.8 | 6.5% | Jan 7, 2025 | Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_... |
| CVE-2024-40749 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | Improper Access Controls allows access to protected views. |
| CVE-2024-40748 | HIGH | 7.5 | 0.4% | Jan 7, 2025 | Lack of output escaping in the id attribute of menu lists. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now