2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23733 | HIGH | 7.5 | 2.3% | Jan 29, 2025 | The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core... |
| CVE-2024-12705 | HIGH | 7.5 | 16.2% | Jan 29, 2025 | Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or i... |
| CVE-2024-11187 | HIGH | 7.5 | 14.7% | Jan 29, 2025 | It is possible to construct a zone such that some queries to it will generate responses containing numerous records in t... |
| CVE-2024-10001 | HIGH | 7.1 | 0.4% | Jan 29, 2025 | A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious cod... |
| CVE-2024-57436 | HIGH | 7.2 | 0.6% | Jan 29, 2025 | RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring... |
| CVE-2024-54462 | HIGH | 7.1 | 0.2% | Jan 29, 2025 | The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious docu... |
| CVE-2024-54461 | HIGH | 7.1 | 0.2% | Jan 29, 2025 | The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious doc... |
| CVE-2024-7695 | HIGH | 8.7 | 0.7% | Jan 29, 2025 | Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient inp... |
| CVE-2024-13696 | HIGH | 7.2 | 0.4% | Jan 29, 2025 | The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored... |
| CVE-2024-12749 | HIGH | 7.1 | 0.6% | Jan 29, 2025 | The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2024-57519 | HIGH | 7.5 | 0.7% | Jan 28, 2025 | An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in ... |
| CVE-2024-56529 | HIGH | 7.1 | 0.4% | Jan 28, 2025 | Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a sess... |
| CVE-2024-48310 | HIGH | 7.5 | 0.5% | Jan 28, 2025 | AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers ... |
| CVE-2024-57376 | HIGH | 8.8 | 3.6% | Jan 28, 2025 | Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C... |
| CVE-2024-55968 | HIGH | 8.8 | 1.0% | Jan 28, 2025 | An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handli... |
| CVE-2024-40677 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections... |
| CVE-2024-40676 | HIGH | 7.7 | 0.2% | Jan 28, 2025 | In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an ... |
| CVE-2024-40675 | HIGH | 7.5 | 0.3% | Jan 28, 2025 | In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead ... |
| CVE-2024-40672 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permis... |
| CVE-2024-40670 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil... |
| CVE-2024-40669 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil... |
| CVE-2024-40651 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation ... |
| CVE-2024-40649 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation ... |
| CVE-2024-34748 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. Thi... |
| CVE-2024-34733 | HIGH | 8.4 | 0.1% | Jan 28, 2025 | In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. Th... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now