2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49559 | HIGH | 8.8 | 0.5% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password... |
| CVE-2024-48831 | HIGH | 8.4 | 0.2% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthent... |
| CVE-2024-48830 | HIGH | 7.8 | 0.7% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization... |
| CVE-2024-48013 | HIGH | 8.8 | 0.6% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecess... |
| CVE-2024-12971 | HIGH | 8.8 | 59.4% | Mar 17, 2025 | Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affec... |
| CVE-2024-54449 | HIGH | 8.8 | 0.6% | Mar 14, 2025 | The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticat... |
| CVE-2024-54448 | HIGH | 7.2 | 0.5% | Mar 14, 2025 | The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying ... |
| CVE-2024-54447 | HIGH | 7.1 | 0.3% | Mar 14, 2025 | Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time... |
| CVE-2024-54446 | HIGH | 7.1 | 0.3% | Mar 14, 2025 | Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a ... |
| CVE-2024-54445 | HIGH | 8.7 | 0.3% | Mar 14, 2025 | Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-base... |
| CVE-2024-12245 | HIGH | 8.7 | 0.3% | Mar 14, 2025 | Logout functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-bas... |
| CVE-2024-12019 | HIGH | 7.1 | 0.4% | Mar 14, 2025 | The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read... |
| CVE-2024-46662 | HIGH | 8.8 | 2.1% | Mar 14, 2025 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions ... |
| CVE-2024-45643 | HIGH | 7.5 | 0.2% | Mar 14, 2025 | IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt ... |
| CVE-2024-13773 | HIGH | 7.5 | 0.3% | Mar 14, 2025 | The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information... |
| CVE-2024-12810 | HIGH | 8.1 | 0.3% | Mar 14, 2025 | The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modificat... |
| CVE-2024-8176 | HIGH | 7.5 | 1.3% | Mar 14, 2025 | A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XM... |
| CVE-2024-13913 | HIGH | 8.8 | 2.4% | Mar 14, 2025 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2024-13376 | HIGH | 8.8 | 0.3% | Mar 14, 2025 | The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat... |
| CVE-2024-11283 | HIGH | 7.5 | 0.4% | Mar 14, 2025 | The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th... |
| CVE-2024-55549 | HIGH | 7.8 | 0.3% | Mar 14, 2025 | xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. |
| CVE-2024-53406 | HIGH | 8.8 | 0.6% | Mar 13, 2025 | Espressif Esp idf v5.3.0 is vulnerable to Insecure Permissions resulting in Authentication bypass. In the reconnection p... |
| CVE-2024-10942 | HIGH | 7.5 | 0.5% | Mar 13, 2025 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,... |
| CVE-2024-8402 | HIGH | 7.4 | 0.2% | Mar 13, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from... |
| CVE-2024-13891 | HIGH | 7.1 | 0.3% | Mar 13, 2025 | The Schedule WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the pa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now