2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10445 | MEDIUM | 5.3 | 0.4% | Mar 19, 2025 | Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-653... |
| CVE-2024-57151 | MEDIUM | 6.8 | 0.4% | Mar 18, 2025 | SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via... |
| CVE-2024-57170 | MEDIUM | 6.5 | 0.8% | Mar 18, 2025 | SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" paramete... |
| CVE-2024-49822 | MEDIUM | 4.1 | 0.3% | Mar 18, 2025 | IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authentica... |
| CVE-2024-44314 | MEDIUM | 6.5 | 0.3% | Mar 18, 2025 | TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthor... |
| CVE-2024-41975 | MEDIUM | 5.3 | 0.4% | Mar 18, 2025 | An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs p... |
| CVE-2024-54565 | MEDIUM | 6.2 | 0.2% | Mar 17, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access se... |
| CVE-2024-54559 | MEDIUM | 5.5 | 0.2% | Mar 17, 2025 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app may be able to access se... |
| CVE-2024-8510 | MEDIUM | 5.3 | 0.4% | Mar 17, 2025 | N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Custom... |
| CVE-2024-44866 | MEDIUM | 6.8 | 0.3% | Mar 17, 2025 | A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary c... |
| CVE-2024-48828 | MEDIUM | 5.5 | 0.2% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Mana... |
| CVE-2024-48017 | MEDIUM | 6.5 | 1.2% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization... |
| CVE-2024-48015 | MEDIUM | 6.7 | 0.6% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization... |
| CVE-2024-9055 | MEDIUM | 4.2 | 0.2% | Mar 17, 2025 | The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allo... |
| CVE-2024-54027 | MEDIUM | 4.4 | 0.1% | Mar 17, 2025 | A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and... |
| CVE-2024-13602 | MEDIUM | 4.8 | 0.2% | Mar 16, 2025 | The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-13126 | MEDIUM | 4.6 | 0.5% | Mar 16, 2025 | The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htac... |
| CVE-2024-58103 | MEDIUM | 5.8 | 0.4% | Mar 16, 2025 | Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReade... |
| CVE-2024-13497 | MEDIUM | 6.1 | 0.3% | Mar 15, 2025 | The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable t... |
| CVE-2024-12336 | MEDIUM | 6.5 | 0.3% | Mar 15, 2025 | The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of ... |
| CVE-2024-29409 | MEDIUM | 5.5 | 0.3% | Mar 14, 2025 | File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Typ... |
| CVE-2024-12020 | MEDIUM | 6.1 | 0.2% | Mar 14, 2025 | There is a reflected cross-site scripting (XSS) within JSP files used to control application appearance. An unauthentica... |
| CVE-2024-40585 | MEDIUM | 6.5 | 0.3% | Mar 14, 2025 | An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2... |
| CVE-2024-47573 | MEDIUM | 6.5 | 0.2% | Mar 14, 2025 | An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2... |
| CVE-2024-45638 | MEDIUM | 4.4 | 0.1% | Mar 14, 2025 | IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now