2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52878HIGH7.5An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-52877HIGH7.5An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kern...
CVE-2024-13914HIGH7.2The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an...
CVE-2024-45067HIGH8.2Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticat...
CVE-2024-56427MEDIUM6.5An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200,...
CVE-2024-55569HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2024-58101HIGH8.1Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to st...
CVE-2024-57096MEDIUM5.5An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.
CVE-2024-45516MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4...
CVE-2024-56157MEDIUM6.3iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV c...
CVE-2024-52601MEDIUM6.5iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account havi...
CVE-2024-10865CRITICAL9.4Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This i...
CVE-2024-10864HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText Advanced ...
CVE-2024-57273MEDIUM5.4Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XS...
CVE-2024-54780HIGH8.8Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in th...
CVE-2024-54779MEDIUM5.4Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XS...
CVE-2024-24780CRITICAL9.8Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create ...
CVE-2024-8988MEDIUM5.3The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ...
CVE-2024-13940MEDIUM5.5The Ninja Forms Webhooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in...
CVE-2024-52290MEDIUM5.4LF Edge eKuiper is a lightweight internet of things (IoT) data analytics and stream processing engine. Prior to version ...
CVE-2024-48869MEDIUM6.1Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when...
CVE-2024-47800MEDIUM6.7Uncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enabl...
CVE-2024-47795MEDIUM6.7Uncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authe...
CVE-2024-47550MEDIUM6.7Incorrect default permissions for some Endurance Gaming Mode software installers may allow an authenticated user to pote...
CVE-2024-46895MEDIUM6.7Uncontrolled search path for some Intel(R) Arc™ & Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now