2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50567 | HIGH | 7.2 | 2.3% | Feb 11, 2025 | An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0... |
| CVE-2024-40591 | HIGH | 7.2 | 0.6% | Feb 11, 2025 | An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 ... |
| CVE-2024-40584 | HIGH | 7.2 | 1.9% | Feb 11, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-35279 | HIGH | 8.1 | 0.9% | Feb 11, 2025 | A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 ... |
| CVE-2024-33504 | HIGH | 7.7 | 0.3% | Feb 11, 2025 | A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.... |
| CVE-2024-47908 | HIGH | 7.2 | 22.0% | Feb 11, 2025 | OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker ... |
| CVE-2024-13813 | HIGH | 7.1 | 0.2% | Feb 11, 2025 | Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to d... |
| CVE-2024-10644 | HIGH | 7.2 | 2.2% | Feb 11, 2025 | Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows ... |
| CVE-2024-33659 | HIGH | 8.8 | 0.2% | Feb 11, 2025 | AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker... |
| CVE-2024-54089 | HIGH | 8.7 | 0.2% | Feb 11, 2025 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v... |
| CVE-2024-54015 | HIGH | 8.7 | 0.5% | Feb 11, 2025 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All ve... |
| CVE-2024-53977 | HIGH | 7.8 | 0.1% | Feb 11, 2025 | A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example se... |
| CVE-2024-53648 | HIGH | 7 | 0.3% | Feb 11, 2025 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All ve... |
| CVE-2024-45386 | HIGH | 8.8 | 0.5% | Feb 11, 2025 | A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Up... |
| CVE-2024-13643 | HIGH | 8.8 | 0.6% | Feb 11, 2025 | The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modi... |
| CVE-2024-57177 | HIGH | 7.3 | 0.3% | Feb 10, 2025 | A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially ... |
| CVE-2024-8550 | HIGH | 7.5 | 0.5% | Feb 10, 2025 | A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4... |
| CVE-2024-46436 | HIGH | 8.3 | 0.4% | Feb 10, 2025 | Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the ... |
| CVE-2024-46435 | HIGH | 8 | 0.8% | Feb 10, 2025 | A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote a... |
| CVE-2024-46434 | HIGH | 8.8 | 0.9% | Feb 10, 2025 | Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized rem... |
| CVE-2024-46433 | HIGH | 8.8 | 0.5% | Feb 10, 2025 | A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the... |
| CVE-2024-46432 | HIGH | 8.8 | 0.6% | Feb 10, 2025 | Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POS... |
| CVE-2024-46431 | HIGH | 8 | 0.4% | Feb 10, 2025 | Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can e... |
| CVE-2024-46429 | HIGH | 8.8 | 0.6% | Feb 10, 2025 | A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access t... |
| CVE-2024-42512 | HIGH | 8.6 | 0.5% | Feb 10, 2025 | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now