2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55597 | HIGH | 7.2 | 0.5% | Mar 11, 2025 | A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 thr... |
| CVE-2024-55590 | HIGH | 8.8 | 1.0% | Mar 11, 2025 | Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE... |
| CVE-2024-54026 | HIGH | 8.8 | 0.4% | Mar 11, 2025 | An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 t... |
| CVE-2024-54018 | HIGH | 7.2 | 9.2% | Mar 11, 2025 | Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox befo... |
| CVE-2024-52961 | HIGH | 8.8 | 0.5% | Mar 11, 2025 | An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo... |
| CVE-2024-52960 | HIGH | 8.8 | 0.3% | Mar 11, 2025 | A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 ... |
| CVE-2024-51321 | HIGH | 7.6 | 0.3% | Mar 11, 2025 | In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to... |
| CVE-2024-51319 | HIGH | 7.3 | 0.4% | Mar 11, 2025 | A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attac... |
| CVE-2024-45328 | HIGH | 7.8 | 0.1% | Mar 11, 2025 | An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged admin... |
| CVE-2024-45324 | HIGH | 7.2 | 0.7% | Mar 11, 2025 | A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2... |
| CVE-2024-54084 | HIGH | 7 | 0.1% | Mar 11, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause a Time-of-check Time-of-use (TOCTOU) Race Condition ... |
| CVE-2024-56182 | HIGH | 8.4 | 0.2% | Mar 11, 2025 | A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12... |
| CVE-2024-56181 | HIGH | 8.4 | 0.2% | Mar 11, 2025 | A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07)... |
| CVE-2024-13864 | HIGH | 7.1 | 0.3% | Mar 11, 2025 | The Countdown Timer WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2024-13862 | HIGH | 7.1 | 0.3% | Mar 11, 2025 | The S3Bubble Media Streaming (AWS|Elementor|YouTube|Vimeo Functionality) WordPress plugin through 8.0 does not sanitise ... |
| CVE-2024-13836 | HIGH | 7.1 | 0.3% | Mar 11, 2025 | The WP Login Control WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-13574 | HIGH | 7.1 | 0.3% | Mar 11, 2025 | The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2024-12010 | HIGH | 7.2 | 1.1% | Mar 11, 2025 | A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware v... |
| CVE-2024-12009 | HIGH | 7.2 | 1.1% | Mar 11, 2025 | A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.... |
| CVE-2024-11253 | HIGH | 7.2 | 1.1% | Mar 11, 2025 | A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyx... |
| CVE-2024-56192 | HIGH | 7.8 | 0.1% | Mar 10, 2025 | In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This co... |
| CVE-2024-56191 | HIGH | 8.4 | 0.1% | Mar 10, 2025 | In dhd_process_full_gscan_result of dhd_pno.c, there is a possible EoP due to an integer overflow. This could lead to lo... |
| CVE-2024-54546 | HIGH | 7.5 | 0.4% | Mar 10, 2025 | The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to ca... |
| CVE-2024-44227 | HIGH | 7.5 | 0.4% | Mar 10, 2025 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An... |
| CVE-2024-11638 | HIGH | 8.8 | 0.5% | Mar 10, 2025 | The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now