2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50596 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50595 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50594 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50385 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ... |
| CVE-2024-50384 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ... |
| CVE-2024-36465 | HIGH | 8.8 | 23.0% | Apr 2, 2025 | A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiSer... |
| CVE-2024-13567 | HIGH | 7.5 | 0.6% | Apr 1, 2025 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Ex... |
| CVE-2024-54533 | HIGH | 7 | 0.6% | Mar 31, 2025 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS... |
| CVE-2024-12021 | HIGH | 8.5 | 0.3% | Mar 31, 2025 | Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interf... |
| CVE-2024-7577 | HIGH | 7.5 | 0.3% | Mar 29, 2025 | IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation ... |
| CVE-2024-57083 | HIGH | 7.5 | 0.5% | Mar 28, 2025 | A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attac... |
| CVE-2024-54362 | HIGH | 8.1 | 0.4% | Mar 28, 2025 | Path Traversal: '.../...//' vulnerability in boggibill GetShop ecommerce getshop-ecommerce allows Path Traversal.This is... |
| CVE-2024-54291 | HIGH | 8.6 | 0.5% | Mar 28, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 PluginPass plugin... |
| CVE-2024-51624 | HIGH | 7.1 | 0.2% | Mar 28, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jajapagamentos Já-... |
| CVE-2024-48615 | HIGH | 7.5 | 0.4% | Mar 28, 2025 | Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pa... |
| CVE-2024-7407 | HIGH | 8.2 | 0.4% | Mar 28, 2025 | Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords ... |
| CVE-2024-11504 | HIGH | 8.6 | 0.4% | Mar 28, 2025 | Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, w... |
| CVE-2024-13939 | HIGH | 7.5 | 0.3% | Mar 28, 2025 | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the... |
| CVE-2024-49565 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-49564 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-49563 | HIGH | 7.8 | 0.5% | Mar 28, 2025 | Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('... |
| CVE-2024-55073 | HIGH | 7.6 | 0.3% | Mar 27, 2025 | A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ... |
| CVE-2024-12905 | HIGH | 7.5 | 2.2% | Mar 27, 2025 | An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted ... |
| CVE-2024-9773 | HIGH | 8 | 0.2% | Mar 27, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from... |
| CVE-2024-45356 | HIGH | 7.3 | 0.1% | Mar 27, 2025 | A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now