2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13990 | CRITICAL | 9.3 | 0.6% | Sep 19, 2025 | MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were deli... |
| CVE-2024-48851 | HIGH | 7.5 | 0.5% | Sep 18, 2025 | Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an... |
| CVE-2024-25011 | MEDIUM | 5.3 | 0.3% | Sep 18, 2025 | Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication chec... |
| CVE-2024-13151 | CRITICAL | 9.8 | 0.3% | Sep 18, 2025 | CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI In... |
| CVE-2024-48842 | HIGH | 7.3 | 0.2% | Sep 17, 2025 | Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions |
| CVE-2024-13174 | HIGH | 8.6 | 0.3% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E1 Informatics Web... |
| CVE-2024-13149 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ... |
| CVE-2024-12796 | MEDIUM | 5.3 | 0.2% | Sep 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Holistic IT... |
| CVE-2024-12913 | HIGH | 8.8 | 0.2% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communicat... |
| CVE-2024-12367 | HIGH | 8.6 | 0.3% | Sep 16, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Maste... |
| CVE-2024-45434 | CRITICAL | 9.8 | 5.9% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetoo... |
| CVE-2024-45433 | MEDIUM | 6.5 | 0.5% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the B... |
| CVE-2024-45432 | HIGH | 7.5 | 0.7% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK B... |
| CVE-2024-45431 | MEDIUM | 5.3 | 4.4% | Sep 12, 2025 | OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSD... |
| CVE-2024-47120 | MEDIUM | 6.8 | 0.2% | Sep 10, 2025 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their... |
| CVE-2024-45671 | HIGH | 7.5 | 0.2% | Sep 10, 2025 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algor... |
| CVE-2024-45669 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of ... |
| CVE-2024-45325 | MEDIUM | 6.7 | 0.5% | Sep 9, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] i... |
| CVE-2024-48341 | LOW | 3.7 | 0.2% | Sep 8, 2025 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.... |
| CVE-2024-36354 | HIGH | 7.5 | 0.2% | Sep 6, 2025 | Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r... |
| CVE-2024-36352 | HIGH | 8.4 | 0.1% | Sep 6, 2025 | Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, pote... |
| CVE-2024-36346 | MEDIUM | 6 | 0.1% | Sep 6, 2025 | Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to sen... |
| CVE-2024-36342 | HIGH | 8.8 | 0.2% | Sep 6, 2025 | Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in ... |
| CVE-2024-36331 | LOW | 3.2 | 0.1% | Sep 6, 2025 | Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SN... |
| CVE-2024-36326 | HIGH | 8.4 | 0.1% | Sep 6, 2025 | Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now