2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11437 | MEDIUM | 4.9 | 0.5% | Jan 7, 2025 | The Timeline Designer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, a... |
| CVE-2024-55553 | HIGH | 7.5 | 0.8% | Jan 6, 2025 | In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via ... |
| CVE-2024-54767 | HIGH | 7.5 | 1.8% | Jan 6, 2025 | An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sen... |
| CVE-2024-54764 | MEDIUM | 6.5 | 1.0% | Jan 6, 2025 | An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensit... |
| CVE-2024-54763 | MEDIUM | 6.5 | 0.7% | Jan 6, 2025 | An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensiti... |
| CVE-2024-53936 | MEDIUM | 6.3 | 0.2% | Jan 6, 2025 | The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any applicati... |
| CVE-2024-53935 | MEDIUM | 6.5 | 0.2% | Jan 6, 2025 | The com.callos14.callscreen.colorphone (aka iCall OS17 - Color Phone Flash) application through 4.3 for Android enables ... |
| CVE-2024-53934 | HIGH | 7.7 | 0.2% | Jan 6, 2025 | The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2... |
| CVE-2024-53933 | MEDIUM | 6.3 | 0.2% | Jan 6, 2025 | The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Andr... |
| CVE-2024-53932 | CRITICAL | 9.1 | 0.3% | Jan 6, 2025 | The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.... |
| CVE-2024-53931 | CRITICAL | 9.1 | 0.3% | Jan 6, 2025 | The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any appli... |
| CVE-2024-51741 | MEDIUM | 4.4 | 0.3% | Jan 6, 2025 | Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat... |
| CVE-2024-48457 | HIGH | 7.5 | 3.0% | Jan 6, 2025 | An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ... |
| CVE-2024-48456 | HIGH | 7.5 | 17.3% | Jan 6, 2025 | An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ... |
| CVE-2024-48455 | LOW | 2.7 | 6.2% | Jan 6, 2025 | An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ... |
| CVE-2024-46981 | CRITICAL | 9.8 | 7.8% | Jan 6, 2025 | Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua... |
| CVE-2024-55076 | HIGH | 8.1 | 0.3% | Jan 6, 2025 | Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password. |
| CVE-2024-55075 | MEDIUM | 5.3 | 0.5% | Jan 6, 2025 | Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not sh... |
| CVE-2024-55074 | CRITICAL | 9 | 0.6% | Jan 6, 2025 | The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a cra... |
| CVE-2024-55408 | MEDIUM | 5.3 | 0.2% | Jan 6, 2025 | An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality uti... |
| CVE-2024-55407 | HIGH | 7.8 | 0.2% | Jan 6, 2025 | An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary p... |
| CVE-2024-46209 | MEDIUM | 5.4 | 0.4% | Jan 6, 2025 | A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attacke... |
| CVE-2024-35498 | MEDIUM | 6.1 | 0.4% | Jan 6, 2025 | A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via... |
| CVE-2024-56828 | CRITICAL | 9.8 | 0.9% | Jan 6, 2025 | File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/memb... |
| CVE-2024-55629 | HIGH | 7.5 | 0.5% | Jan 6, 2025 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now