2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13933 | HIGH | 8.8 | 0.2% | Mar 19, 2025 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request F... |
| CVE-2024-12920 | HIGH | 8.8 | 0.4% | Mar 19, 2025 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access ... |
| CVE-2024-12137 | HIGH | 7.6 | 0.2% | Mar 19, 2025 | Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking. T... |
| CVE-2024-12136 | HIGH | 7.8 | 0.1% | Mar 19, 2025 | Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass... |
| CVE-2024-13412 | HIGH | 7.5 | 0.3% | Mar 19, 2025 | The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2024-50631 | HIGH | 7.5 | 24.9% | Mar 19, 2025 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing... |
| CVE-2024-50630 | HIGH | 7.5 | 22.7% | Mar 19, 2025 | Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4... |
| CVE-2024-12295 | HIGH | 8.8 | 0.3% | Mar 19, 2025 | The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers... |
| CVE-2024-10444 | HIGH | 7.5 | 0.2% | Mar 19, 2025 | Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-4... |
| CVE-2024-12563 | HIGH | 8.8 | 0.6% | Mar 18, 2025 | The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214... |
| CVE-2024-44313 | HIGH | 8.1 | 0.6% | Mar 18, 2025 | TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which ... |
| CVE-2024-21760 | HIGH | 8.4 | 0.7% | Mar 18, 2025 | An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4... |
| CVE-2024-23942 | HIGH | 7.1 | 0.1% | Mar 18, 2025 | A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an att... |
| CVE-2024-40635 | HIGH | 7.8 | 0.3% | Mar 17, 2025 | containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.... |
| CVE-2024-54525 | HIGH | 8.8 | 0.5% | Mar 17, 2025 | A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia ... |
| CVE-2024-44276 | HIGH | 7.3 | 0.2% | Mar 17, 2025 | This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and i... |
| CVE-2024-49561 | HIGH | 7.8 | 0.2% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Ass... |
| CVE-2024-49559 | HIGH | 8.8 | 0.5% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password... |
| CVE-2024-48831 | HIGH | 8.4 | 0.2% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthent... |
| CVE-2024-48830 | HIGH | 7.8 | 0.7% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization... |
| CVE-2024-48013 | HIGH | 8.8 | 0.6% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecess... |
| CVE-2024-12971 | HIGH | 8.8 | 59.4% | Mar 17, 2025 | Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affec... |
| CVE-2024-54449 | HIGH | 8.8 | 0.6% | Mar 14, 2025 | The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticat... |
| CVE-2024-54448 | HIGH | 7.2 | 0.5% | Mar 14, 2025 | The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying ... |
| CVE-2024-54447 | HIGH | 7.1 | 0.3% | Mar 14, 2025 | Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now