2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13440 | HIGH | 8.2 | 0.4% | Feb 9, 2025 | The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all v... |
| CVE-2024-57606 | HIGH | 7.5 | 0.5% | Feb 7, 2025 | SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker ... |
| CVE-2024-57357 | HIGH | 8 | 5.9% | Feb 7, 2025 | An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code... |
| CVE-2024-55272 | HIGH | 7.5 | 0.5% | Feb 7, 2025 | An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function... |
| CVE-2024-7425 | HIGH | 7.2 | 0.4% | Feb 7, 2025 | The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege... |
| CVE-2024-9664 | HIGH | 7.2 | 0.7% | Feb 7, 2025 | The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4... |
| CVE-2024-7419 | HIGH | 8.8 | 0.6% | Feb 7, 2025 | The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, ... |
| CVE-2024-52884 | HIGH | 7.5 | 0.1% | Feb 7, 2025 | An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of we... |
| CVE-2024-52883 | HIGH | 7.5 | 0.6% | Feb 7, 2025 | An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnera... |
| CVE-2024-52881 | HIGH | 7.5 | 0.3% | Feb 7, 2025 | An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded ... |
| CVE-2024-48091 | HIGH | 7.8 | 0.2% | Feb 7, 2025 | Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. Thi... |
| CVE-2024-13352 | HIGH | 7.1 | 0.5% | Feb 7, 2025 | The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page... |
| CVE-2024-57609 | HIGH | 8.6 | 0.7% | Feb 6, 2025 | An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute... |
| CVE-2024-57392 | HIGH | 7.5 | 1.1% | Feb 6, 2025 | Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can caus... |
| CVE-2024-56889 | HIGH | 7.5 | 0.6% | Feb 6, 2025 | Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauth... |
| CVE-2024-55241 | HIGH | 8.8 | 0.8% | Feb 6, 2025 | An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the m... |
| CVE-2024-54909 | HIGH | 8.1 | 0.4% | Feb 6, 2025 | A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/... |
| CVE-2024-54171 | HIGH | 7.1 | 0.3% | Feb 6, 2025 | IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticat... |
| CVE-2024-57426 | HIGH | 7.3 | 0.3% | Feb 6, 2025 | NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a mali... |
| CVE-2024-47258 | HIGH | 8.1 | 0.1% | Feb 6, 2025 | 2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verif... |
| CVE-2024-57668 | HIGH | 8.8 | 0.6% | Feb 6, 2025 | In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability. |
| CVE-2024-57610 | HIGH | 7.5 | 1.1% | Feb 6, 2025 | A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user acco... |
| CVE-2024-36558 | HIGH | 7.5 | 0.1% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of ... |
| CVE-2024-36553 | HIGH | 8.1 | 0.3% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack. |
| CVE-2024-39272 | HIGH | 8.2 | 0.5% | Feb 6, 2025 | A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now