2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52878 | HIGH | 7.5 | 0.4% | May 15, 2025 | An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern... |
| CVE-2024-52877 | HIGH | 7.5 | 0.4% | May 15, 2025 | An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern... |
| CVE-2024-13914 | HIGH | 7.2 | 0.7% | May 15, 2025 | The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an... |
| CVE-2024-45067 | HIGH | 8.2 | 0.1% | May 14, 2025 | Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticat... |
| CVE-2024-56427 | MEDIUM | 6.5 | 0.2% | May 14, 2025 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200,... |
| CVE-2024-55569 | HIGH | 7.5 | 0.4% | May 14, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2024-58101 | HIGH | 8.1 | 0.2% | May 14, 2025 | Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to st... |
| CVE-2024-57096 | MEDIUM | 5.5 | 0.1% | May 14, 2025 | An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file. |
| CVE-2024-45516 | MEDIUM | 6.1 | 0.3% | May 14, 2025 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4... |
| CVE-2024-56157 | MEDIUM | 6.3 | 0.2% | May 14, 2025 | iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV c... |
| CVE-2024-52601 | MEDIUM | 6.5 | 0.3% | May 14, 2025 | iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account havi... |
| CVE-2024-10865 | CRITICAL | 9.4 | 0.4% | May 14, 2025 | Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This i... |
| CVE-2024-10864 | HIGH | 7.5 | 0.3% | May 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced ... |
| CVE-2024-57273 | MEDIUM | 5.4 | 1.2% | May 14, 2025 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XS... |
| CVE-2024-54780 | HIGH | 8.8 | 12.0% | May 14, 2025 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in th... |
| CVE-2024-54779 | MEDIUM | 5.4 | 3.7% | May 14, 2025 | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XS... |
| CVE-2024-24780 | CRITICAL | 9.8 | 1.3% | May 14, 2025 | Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create ... |
| CVE-2024-8988 | MEDIUM | 5.3 | 0.2% | May 14, 2025 | The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ... |
| CVE-2024-13940 | MEDIUM | 5.5 | 0.2% | May 14, 2025 | The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in... |
| CVE-2024-52290 | MEDIUM | 5.4 | 0.2% | May 14, 2025 | LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version ... |
| CVE-2024-48869 | MEDIUM | 6.1 | 0.1% | May 13, 2025 | Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when... |
| CVE-2024-47800 | MEDIUM | 6.7 | 0.1% | May 13, 2025 | Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enabl... |
| CVE-2024-47795 | MEDIUM | 6.7 | 0.1% | May 13, 2025 | Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authe... |
| CVE-2024-47550 | MEDIUM | 6.7 | 0.1% | May 13, 2025 | Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to pote... |
| CVE-2024-46895 | MEDIUM | 6.7 | 0.1% | May 13, 2025 | Uncontrolled search path for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now