2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40765 | CRITICAL | 9.8 | 0.8% | Jan 9, 2025 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions ... |
| CVE-2024-53704 | CRITICAL | 9.8 | 95.1% | Jan 9, 2025 | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe... |
| CVE-2024-40762 | CRITICAL | 9.8 | 1.0% | Jan 9, 2025 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator... |
| CVE-2024-13195 | CRITICAL | 9.8 | 0.4% | Jan 9, 2025 | A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been classified as critical. This affects the fun... |
| CVE-2024-13191 | CRITICAL | 9.8 | 0.6% | Jan 8, 2025 | A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function... |
| CVE-2024-13189 | CRITICAL | 9.8 | 0.5% | Jan 8, 2025 | A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file sr... |
| CVE-2024-54676 | CRITICAL | 9.8 | 65.2% | Jan 8, 2025 | Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Def... |
| CVE-2024-11350 | CRITICAL | 9.8 | 0.7% | Jan 8, 2025 | The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i... |
| CVE-2024-11635 | CRITICAL | 9.8 | 1.4% | Jan 8, 2025 | The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi... |
| CVE-2024-11613 | CRITICAL | 9.8 | 4.4% | Jan 8, 2025 | The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrar... |
| CVE-2024-50603 | CRITICAL | 9.8 | 98.5% | Jan 8, 2025 | An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza... |
| CVE-2024-54819 | CRITICAL | 9.1 | 18.2% | Jan 7, 2025 | I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input valid... |
| CVE-2024-35532 | CRITICAL | 9.1 | 0.5% | Jan 7, 2025 | An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attacke... |
| CVE-2024-55414 | CRITICAL | 9.8 | 1.1% | Jan 7, 2025 | A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged u... |
| CVE-2024-50660 | CRITICAL | 9.8 | 0.9% | Jan 7, 2025 | File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload f... |
| CVE-2024-50658 | CRITICAL | 9.8 | 0.8% | Jan 7, 2025 | Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-55556 | CRITICAL | 9.8 | 43.6% | Jan 7, 2025 | A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote com... |
| CVE-2024-56290 | CRITICAL | 9.3 | 0.4% | Jan 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 M... |
| CVE-2024-56284 | CRITICAL | 9.3 | 0.4% | Jan 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sslplugins SSL Wir... |
| CVE-2024-56278 | CRITICAL | 9.1 | 1.8% | Jan 7, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ult... |
| CVE-2024-56273 | CRITICAL | 9.8 | 0.4% | Jan 7, 2025 | Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessin... |
| CVE-2024-49649 | CRITICAL | 9.8 | 0.6% | Jan 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-49222 | CRITICAL | 9.8 | 0.5% | Jan 7, 2025 | Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injecti... |
| CVE-2024-43243 | CRITICAL | 10 | 0.5% | Jan 7, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job-board-light allows U... |
| CVE-2024-8855 | CRITICAL | 9.8 | 0.6% | Jan 7, 2025 | The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now