2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53011 | HIGH | 7.9 | 0.1% | Mar 3, 2025 | Information disclosure may occur due to improper permission and access controls to Video Analytics engine. |
| CVE-2024-49836 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption may occur during the synchronization of the camera`s frame processing pipeline. |
| CVE-2024-45580 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption while handling multuple IOCTL calls from userspace for remote invocation. |
| CVE-2024-43062 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization. |
| CVE-2024-43061 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound mode... |
| CVE-2024-43060 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP. |
| CVE-2024-43059 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node. |
| CVE-2024-43057 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption while processing command in Glink linux. |
| CVE-2024-43055 | HIGH | 7.8 | 0.1% | Mar 3, 2025 | Memory corruption while processing camera use case IOCTL call. |
| CVE-2024-13833 | HIGH | 7.2 | 0.6% | Mar 1, 2025 | The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, ... |
| CVE-2024-13910 | HIGH | 7.2 | 0.9% | Mar 1, 2025 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file ... |
| CVE-2024-13611 | HIGH | 7.5 | 0.5% | Mar 1, 2025 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu... |
| CVE-2024-13911 | HIGH | 7.2 | 0.5% | Mar 1, 2025 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Infor... |
| CVE-2024-12544 | HIGH | 8.8 | 0.7% | Mar 1, 2025 | The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ... |
| CVE-2024-13373 | HIGH | 8.1 | 0.4% | Mar 1, 2025 | The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up... |
| CVE-2024-13568 | HIGH | 7.5 | 0.4% | Mar 1, 2025 | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Informati... |
| CVE-2024-9195 | HIGH | 8.8 | 0.4% | Feb 28, 2025 | The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead t... |
| CVE-2024-13831 | HIGH | 7.2 | 0.5% | Feb 28, 2025 | The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including... |
| CVE-2024-13638 | HIGH | 7.5 | 0.4% | Feb 28, 2025 | The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio... |
| CVE-2024-13796 | HIGH | 7.5 | 0.4% | Feb 28, 2025 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in... |
| CVE-2024-12811 | HIGH | 8.8 | 0.7% | Feb 28, 2025 | The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via s... |
| CVE-2024-38291 | HIGH | 8.8 | 0.3% | Feb 27, 2025 | In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege esc... |
| CVE-2024-41340 | HIGH | 8.4 | 0.2% | Feb 27, 2025 | An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior t... |
| CVE-2024-41339 | HIGH | 8.8 | 0.6% | Feb 27, 2025 | An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620... |
| CVE-2024-41338 | HIGH | 7.5 | 0.4% | Feb 27, 2025 | A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now