2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13617 | HIGH | 8.6 | 0.4% | Mar 25, 2025 | The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unau... |
| CVE-2024-10210 | HIGH | 8.4 | 0.4% | Mar 25, 2025 | An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an ... |
| CVE-2024-8313 | HIGH | 8.7 | 0.2% | Mar 25, 2025 | An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an I... |
| CVE-2024-45484 | HIGH | 7.2 | 0.2% | Mar 25, 2025 | An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used... |
| CVE-2024-45483 | HIGH | 7 | 0.2% | Mar 25, 2025 | A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow ... |
| CVE-2024-45482 | HIGH | 8.5 | 0.1% | Mar 25, 2025 | An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may a... |
| CVE-2024-45481 | HIGH | 8.5 | 0.1% | Mar 25, 2025 | An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may all... |
| CVE-2024-10209 | HIGH | 8.5 | 0.1% | Mar 25, 2025 | An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may ... |
| CVE-2024-8774 | HIGH | 7.7 | 0.3% | Mar 24, 2025 | The SIMPLE.ERP client stores superuser password in a recoverable format, allowing any authenticated SIMPLE.ERP user to e... |
| CVE-2024-8773 | HIGH | 8.3 | 0.4% | Mar 24, 2025 | SIMPLE.ERP client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt... |
| CVE-2024-53350 | HIGH | 7.4 | 0.4% | Mar 21, 2025 | Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escal... |
| CVE-2024-53349 | HIGH | 7.4 | 0.4% | Mar 21, 2025 | Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escal... |
| CVE-2024-53348 | HIGH | 7.4 | 0.3% | Mar 21, 2025 | LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive informati... |
| CVE-2024-57490 | HIGH | 7.7 | 0.4% | Mar 21, 2025 | Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system ... |
| CVE-2024-13903 | HIGH | 7.5 | 0.7% | Mar 21, 2025 | A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulne... |
| CVE-2024-54551 | HIGH | 7.5 | 0.6% | Mar 21, 2025 | The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, mac... |
| CVE-2024-44305 | HIGH | 7.8 | 0.1% | Mar 21, 2025 | This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able t... |
| CVE-2024-44199 | HIGH | 7.1 | 0.2% | Mar 21, 2025 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may... |
| CVE-2024-57440 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webpr... |
| CVE-2024-13921 | HIGH | 7.2 | 0.6% | Mar 20, 2025 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versio... |
| CVE-2024-9920 | HIGH | 8.8 | 1.2% | Mar 20, 2025 | In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, ... |
| CVE-2024-9919 | HIGH | 8.4 | 0.3% | Mar 20, 2025 | A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauth... |
| CVE-2024-9847 | HIGH | 8 | 0.3% | Mar 20, 2025 | FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable... |
| CVE-2024-9606 | HIGH | 7.5 | 0.7% | Mar 20, 2025 | In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerabi... |
| CVE-2024-9597 | HIGH | 7.1 | 0.3% | Mar 20, 2025 | A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attac... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now