2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13656 | HIGH | 8.1 | 0.4% | Feb 12, 2025 | The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification ... |
| CVE-2024-13654 | HIGH | 8.1 | 0.4% | Feb 12, 2025 | The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of dat... |
| CVE-2024-13653 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of dat... |
| CVE-2024-29172 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attack... |
| CVE-2024-29171 | HIGH | 7.5 | 0.3% | Feb 12, 2025 | Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vuln... |
| CVE-2024-0112 | HIGH | 7.5 | 0.2% | Feb 12, 2025 | NVIDIA Jetson AGX Orin™ and NVIDIA IGX Orin software contain a vulnerability where an attacker can cause an improper inp... |
| CVE-2024-33469 | HIGH | 7.9 | 0.2% | Feb 11, 2025 | An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code ... |
| CVE-2024-21925 | HIGH | 8.2 | 0.2% | Feb 11, 2025 | Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading ... |
| CVE-2024-21924 | HIGH | 8.2 | 0.2% | Feb 11, 2025 | SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services h... |
| CVE-2024-0179 | HIGH | 8.2 | 0.2% | Feb 11, 2025 | SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overw... |
| CVE-2024-21966 | HIGH | 7.3 | 0.2% | Feb 11, 2025 | A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation,... |
| CVE-2024-12551 | HIGH | 7.8 | 0.4% | Feb 11, 2025 | Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabilit... |
| CVE-2024-12550 | HIGH | 7.8 | 0.3% | Feb 11, 2025 | Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerabili... |
| CVE-2024-12549 | HIGH | 7.8 | 0.3% | Feb 11, 2025 | Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerabilit... |
| CVE-2024-12547 | HIGH | 8.8 | 0.8% | Feb 11, 2025 | Tungsten Automation Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabili... |
| CVE-2024-52968 | HIGH | 8.4 | 0.2% | Feb 11, 2025 | An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to Ma... |
| CVE-2024-50569 | HIGH | 7.2 | 1.9% | Feb 11, 2025 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 ... |
| CVE-2024-50567 | HIGH | 7.2 | 2.3% | Feb 11, 2025 | An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0... |
| CVE-2024-40591 | HIGH | 7.2 | 0.6% | Feb 11, 2025 | An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 ... |
| CVE-2024-40584 | HIGH | 7.2 | 1.9% | Feb 11, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-35279 | HIGH | 8.1 | 0.9% | Feb 11, 2025 | A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 ... |
| CVE-2024-33504 | HIGH | 7.7 | 0.3% | Feb 11, 2025 | A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.... |
| CVE-2024-47908 | HIGH | 7.2 | 22.0% | Feb 11, 2025 | OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker ... |
| CVE-2024-13813 | HIGH | 7.1 | 0.2% | Feb 11, 2025 | Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to d... |
| CVE-2024-10644 | HIGH | 7.2 | 2.2% | Feb 11, 2025 | Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now