2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13330 | HIGH | 7.1 | 0.5% | Feb 4, 2025 | The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2024-13329 | HIGH | 7.1 | 0.3% | Feb 4, 2025 | The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2024-47770 | HIGH | 8 | 0.2% | Feb 3, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin... |
| CVE-2024-35177 | HIGH | 7.8 | 0.3% | Feb 3, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin... |
| CVE-2024-57451 | HIGH | 7.5 | 0.9% | Feb 3, 2025 | ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which ... |
| CVE-2024-56903 | HIGH | 8.1 | 0.3% | Feb 3, 2025 | Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against ... |
| CVE-2024-56902 | HIGH | 7.5 | 21.3% | Feb 3, 2025 | Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which ... |
| CVE-2024-56901 | HIGH | 8.8 | 1.7% | Feb 3, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less tha... |
| CVE-2024-56898 | HIGH | 8.8 | 2.4% | Feb 3, 2025 | Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p... |
| CVE-2024-34897 | HIGH | 7.5 | 0.4% | Feb 3, 2025 | Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability. |
| CVE-2024-34896 | HIGH | 7.5 | 0.4% | Feb 3, 2025 | An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected f... |
| CVE-2024-57968 | HIGH | 8.8 | 30.3% | Feb 3, 2025 | Advantive VeraCore before 2024.4.2.1 allows remote authenticated users to upload files to unintended folders (e.g., ones... |
| CVE-2024-57669 | HIGH | 7.5 | 0.9% | Feb 3, 2025 | Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive inf... |
| CVE-2024-57452 | HIGH | 7.5 | 0.4% | Feb 3, 2025 | ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows ... |
| CVE-2024-56921 | HIGH | 7.5 | 0.4% | Feb 3, 2025 | An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF ... |
| CVE-2024-12859 | HIGH | 8.8 | 0.6% | Feb 3, 2025 | The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu... |
| CVE-2024-12511 | HIGH | 7.6 | 0.6% | Feb 3, 2025 | With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This... |
| CVE-2024-57238 | HIGH | 7.3 | 0.3% | Feb 3, 2025 | Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The ... |
| CVE-2024-56161 | HIGH | 7.2 | 0.5% | Feb 3, 2025 | Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator pri... |
| CVE-2024-49843 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption while processing IOCTL from user space to handle GPU AHB bus error. |
| CVE-2024-49840 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality. |
| CVE-2024-49838 | HIGH | 7.5 | 0.3% | Feb 3, 2025 | Information disclosure while parsing the OCI IE with invalid length. |
| CVE-2024-49837 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption while reading CPU state data during guest VM suspend. |
| CVE-2024-49834 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption while power-up or power-down sequence of the camera sensor. |
| CVE-2024-49833 | HIGH | 7.8 | 0.1% | Feb 3, 2025 | Memory corruption can occur in the camera when an invalid CID is used. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now