2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54171 | HIGH | 7.1 | 0.3% | Feb 6, 2025 | IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticat... |
| CVE-2024-57426 | HIGH | 7.3 | 0.3% | Feb 6, 2025 | NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a mali... |
| CVE-2024-47258 | HIGH | 8.1 | 0.1% | Feb 6, 2025 | 2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verif... |
| CVE-2024-57668 | HIGH | 8.8 | 0.6% | Feb 6, 2025 | In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability. |
| CVE-2024-57610 | HIGH | 7.5 | 1.1% | Feb 6, 2025 | A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user acco... |
| CVE-2024-36558 | HIGH | 7.5 | 0.1% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of ... |
| CVE-2024-36553 | HIGH | 8.1 | 0.3% | Feb 6, 2025 | Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack. |
| CVE-2024-39272 | HIGH | 8.2 | 0.5% | Feb 6, 2025 | A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.... |
| CVE-2024-39033 | HIGH | 7.5 | 0.3% | Feb 6, 2025 | In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows u... |
| CVE-2024-24911 | HIGH | 7.5 | 0.4% | Feb 6, 2025 | In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, ... |
| CVE-2024-57962 | HIGH | 7.5 | 0.2% | Feb 6, 2025 | Vulnerability of incomplete verification information in the VPN service module Impact: Successful exploitation of this v... |
| CVE-2024-57960 | HIGH | 7.5 | 0.2% | Feb 6, 2025 | Input verification vulnerability in the ExternalStorageProvider module Impact: Successful exploitation of this vulnerabi... |
| CVE-2024-57957 | HIGH | 7.5 | 0.3% | Feb 6, 2025 | Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vul... |
| CVE-2024-57956 | HIGH | 7.5 | 0.2% | Feb 6, 2025 | Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability ... |
| CVE-2024-57955 | HIGH | 7.5 | 0.2% | Feb 6, 2025 | Arbitrary write vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect se... |
| CVE-2024-57954 | HIGH | 7.5 | 0.2% | Feb 6, 2025 | Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability ... |
| CVE-2024-12602 | HIGH | 7.5 | 0.2% | Feb 6, 2025 | Identity verification vulnerability in the ParamWatcher module Impact: Successful exploitation of this vulnerability may... |
| CVE-2024-45626 | HIGH | 7.5 | 0.7% | Feb 6, 2025 | Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded mem... |
| CVE-2024-37358 | HIGH | 7.5 | 0.8% | Feb 6, 2025 | Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from bot... |
| CVE-2024-13487 | HIGH | 7.3 | 0.7% | Feb 6, 2025 | The The CURCY – Multi Currency for WooCommerce – The best free currency exchange plugin – Run smoothly on WooCommerce 9.... |
| CVE-2024-51450 | HIGH | 8.8 | 1.0% | Feb 6, 2025 | IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary com... |
| CVE-2024-49814 | HIGH | 7.8 | 0.2% | Feb 6, 2025 | IBM Security Verify Access Appliance 10.0.0 through 10.0.3 could allow a locally authenticated user to increase their pr... |
| CVE-2024-57699 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, conta... |
| CVE-2024-57086 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the function fieldsToJson of node-opcua-alarm-condition v2.134.0 allows attackers to cause a De... |
| CVE-2024-57085 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Se... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now