2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57072 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A prototype pollution in the lib.requireFromString function of module-from-string v3.3.1 allows attackers to cause a Den... |
| CVE-2024-57071 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.combine function of php-parser v3.2.1 allows attackers to cause a Denial of Service (Do... |
| CVE-2024-57069 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib function of expand-object v0.4.2 allows attackers to cause a Denial of Service (DoS) vi... |
| CVE-2024-57068 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.mutateMergeDeep function of @tanstack/form-core v0.35.0 allows attackers to cause a Den... |
| CVE-2024-57067 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.parse function of dot-qs v0.2.0 allows attackers to cause a Denial of Service (DoS) via... |
| CVE-2024-57066 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.deep function of @ndhoule/defaults v2.0.1 allows attackers to cause a Denial of Service... |
| CVE-2024-57065 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A prototype pollution in the lib.createPath function of utile v0.3.0 allows attackers to cause a Denial of Service (DoS)... |
| CVE-2024-57064 | HIGH | 7.5 | 0.4% | Feb 5, 2025 | A prototype pollution in the lib.setValue function of @syncfusion/ej2-spreadsheet v27.2.2 allows attackers to cause a De... |
| CVE-2024-57063 | HIGH | 7.5 | 0.5% | Feb 5, 2025 | A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (Do... |
| CVE-2024-48394 | HIGH | 7.8 | 0.1% | Feb 5, 2025 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which... |
| CVE-2024-39564 | HIGH | 8.7 | 0.4% | Feb 5, 2025 | This is a similar, but different vulnerability than the issue reported as CVE-2024-39549. A double-free vulnerability i... |
| CVE-2024-2878 | HIGH | 7.5 | 17.6% | Feb 5, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16... |
| CVE-2024-9631 | HIGH | 7.5 | 0.7% | Feb 5, 2025 | An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 pr... |
| CVE-2024-49352 | HIGH | 7.1 | 0.4% | Feb 5, 2025 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to... |
| CVE-2024-11468 | HIGH | 7.8 | 0.2% | Feb 4, 2025 | Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installa... |
| CVE-2024-11467 | HIGH | 7.8 | 0.2% | Feb 4, 2025 | Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successf... |
| CVE-2024-13723 | HIGH | 7.2 | 1.2% | Feb 4, 2025 | The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrat... |
| CVE-2024-55948 | HIGH | 8.2 | 0.2% | Feb 4, 2025 | Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR re... |
| CVE-2024-43187 | HIGH | 7.5 | 0.2% | Feb 4, 2025 | IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 transmits sensitive or security-critical data i... |
| CVE-2024-23690 | HIGH | 7.2 | 1.2% | Feb 4, 2025 | The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interfac... |
| CVE-2024-40891 | HIGH | 8.8 | 19.4% | Feb 4, 2025 | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the le... |
| CVE-2024-40890 | HIGH | 8.8 | 19.3% | Feb 4, 2025 | **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL... |
| CVE-2024-10239 | HIGH | 7.2 | 0.5% | Feb 4, 2025 | A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with admin... |
| CVE-2024-10238 | HIGH | 7.2 | 0.5% | Feb 4, 2025 | A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can uplo... |
| CVE-2024-10237 | HIGH | 7.2 | 0.2% | Feb 4, 2025 | There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now