2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52976 | HIGH | 7.8 | 0.2% | May 1, 2025 | Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attacker... |
| CVE-2024-11994 | MEDIUM | 5.7 | 0.2% | May 1, 2025 | APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the na... |
| CVE-2024-11390 | MEDIUM | 5.4 | 0.3% | May 1, 2025 | Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s bro... |
| CVE-2024-13381 | MEDIUM | 4.8 | 0.2% | May 1, 2025 | The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could... |
| CVE-2024-13845 | MEDIUM | 5.5 | 0.2% | May 1, 2025 | The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ... |
| CVE-2024-30146 | LOW | 2.7 | 0.2% | Apr 30, 2025 | Improper access control of endpoint in HCL Domino Leap allows certain admin users to import applications from the server... |
| CVE-2024-30145 | MEDIUM | 6.1 | 0.2% | Apr 30, 2025 | Multiple vectors in HCL Domino Volt and Domino Leap allow client-side script injection in the authoring environment and ... |
| CVE-2024-30115 | MEDIUM | 5.4 | 0.2% | Apr 30, 2025 | Insufficient sanitization policy in HCL Leap allows client-side script injection in the deployed application through the... |
| CVE-2024-6032 | HIGH | 7.8 | 0.5% | Apr 30, 2025 | Tesla Model S Iris Modem ql_atfwd Command Injection Code Execution Vulnerability. This vulnerability allows local attack... |
| CVE-2024-6031 | HIGH | 7.8 | 0.2% | Apr 30, 2025 | Tesla Model S oFono AT Command Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local ... |
| CVE-2024-6030 | HIGH | 7 | 0.1% | Apr 30, 2025 | Tesla Model S oFono Unnecessary Privileges Sandbox Escape Vulnerability. This vulnerability allows local attackers to es... |
| CVE-2024-6029 | MEDIUM | 5 | 0.2% | Apr 30, 2025 | Tesla Model S Iris Modem Race Condition Firewall Bypass Vulnerability. This vulnerability allows network-adjacent attack... |
| CVE-2024-13943 | HIGH | 7.8 | 0.1% | Apr 30, 2025 | Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerabil... |
| CVE-2024-9877 | MEDIUM | 5.3 | 0.2% | Apr 30, 2025 | : Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue af... |
| CVE-2024-9876 | HIGH | 8.5 | 0.2% | Apr 30, 2025 | : Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC... |
| CVE-2024-47784 | LOW | 2.6 | 0.2% | Apr 30, 2025 | Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in th... |
| CVE-2024-57698 | HIGH | 7.5 | 0.3% | Apr 29, 2025 | An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes with... |
| CVE-2024-58099 | MEDIUM | 5.5 | 0.2% | Apr 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_... |
| CVE-2024-12273 | LOW | 3.5 | 0.2% | Apr 29, 2025 | The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could... |
| CVE-2024-11922 | MEDIUM | 5.4 | 0.2% | Apr 28, 2025 | Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an a... |
| CVE-2024-10635 | MEDIUM | 5.3 | 0.2% | Apr 28, 2025 | Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthent... |
| CVE-2024-12706 | LOW | 2.1 | 0.2% | Apr 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital ... |
| CVE-2024-32499 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed. |
| CVE-2024-9771 | LOW | 3.5 | 0.2% | Apr 28, 2025 | The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-13688 | MEDIUM | 5.3 | 0.3% | Apr 28, 2025 | The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protectio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now