2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48615 | HIGH | 7.5 | 0.4% | Mar 28, 2025 | Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pa... |
| CVE-2024-7407 | HIGH | 8.2 | 0.4% | Mar 28, 2025 | Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords ... |
| CVE-2024-11504 | HIGH | 8.6 | 0.4% | Mar 28, 2025 | Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, w... |
| CVE-2024-13939 | HIGH | 7.5 | 0.3% | Mar 28, 2025 | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the... |
| CVE-2024-49565 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-49564 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-49563 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-55073 | HIGH | 7.6 | 0.3% | Mar 27, 2025 | A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ... |
| CVE-2024-12905 | HIGH | 7.5 | 2.2% | Mar 27, 2025 | An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted ... |
| CVE-2024-9773 | HIGH | 8 | 0.2% | Mar 27, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from... |
| CVE-2024-45356 | HIGH | 7.3 | 0.1% | Mar 27, 2025 | A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida... |
| CVE-2024-45352 | HIGH | 8.8 | 0.3% | Mar 27, 2025 | An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by impro... |
| CVE-2024-45351 | HIGH | 7.8 | 0.2% | Mar 26, 2025 | A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by imp... |
| CVE-2024-13889 | HIGH | 7.2 | 0.7% | Mar 26, 2025 | The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ... |
| CVE-2024-13801 | HIGH | 8.1 | 0.3% | Mar 26, 2025 | The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a ... |
| CVE-2024-13146 | HIGH | 8.8 | 0.2% | Mar 26, 2025 | The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow att... |
| CVE-2024-31896 | HIGH | 7.5 | 0.2% | Mar 25, 2025 | IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow... |
| CVE-2024-58105 | HIGH | 7.8 | 0.2% | Mar 25, 2025 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ... |
| CVE-2024-58104 | HIGH | 7.8 | 0.2% | Mar 25, 2025 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker ... |
| CVE-2024-12169 | HIGH | 8.7 | 0.4% | Mar 25, 2025 | A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allo... |
| CVE-2024-53678 | HIGH | 8.8 | 0.6% | Mar 25, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users ... |
| CVE-2024-13690 | HIGH | 7.2 | 0.3% | Mar 25, 2025 | The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submi... |
| CVE-2024-44903 | HIGH | 7.5 | 0.3% | Mar 25, 2025 | SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is ava... |
| CVE-2024-13863 | HIGH | 7.1 | 0.3% | Mar 25, 2025 | The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputt... |
| CVE-2024-13618 | HIGH | 7.2 | 0.3% | Mar 25, 2025 | The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now