2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42212 | MEDIUM | 5.4 | 0.2% | May 5, 2025 | HCL BigFix Compliance is affected by an improper or missing SameSite attribute. This can lead to Cross-Site Request For... |
| CVE-2024-57235 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface pa... |
| CVE-2024-57234 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p... |
| CVE-2024-57233 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface pa... |
| CVE-2024-57232 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p... |
| CVE-2024-57231 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p... |
| CVE-2024-57230 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p... |
| CVE-2024-57229 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname ... |
| CVE-2024-51991 | MEDIUM | 4.9 | 0.3% | May 5, 2025 | October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authen... |
| CVE-2024-11615 | MEDIUM | 5.3 | 0.4% | May 5, 2025 | The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1... |
| CVE-2024-58237 | MEDIUM | 5.5 | 0.2% | May 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet poi... |
| CVE-2024-58100 | MEDIUM | 5.5 | 0.2% | May 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: check changes_pkt_data property for extension ... |
| CVE-2024-58098 | MEDIUM | 5.5 | 0.2% | May 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: track changes_pkt_data property for global fun... |
| CVE-2024-58134 | HIGH | 8.1 | 0.4% | May 3, 2025 | Mojolicious versions from 0.999922 for Perl uses a hard coded string, or the application's class name, as an HMAC sessio... |
| CVE-2024-41753 | MEDIUM | 6.1 | 0.2% | May 3, 2025 | IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross... |
| CVE-2024-58135 | MEDIUM | 5.3 | 0.5% | May 3, 2025 | Mojolicious versions from 7.28 through 9.45 for Perl will generate weak HMAC session cookie secrets via "mojo generate a... |
| CVE-2024-13738 | HIGH | 7.3 | 0.4% | May 3, 2025 | The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-55069 | MEDIUM | 5.3 | 0.3% | May 2, 2025 | ffmpeg 7.1 is vulnerable to Null Pointer Dereference in function iamf_read_header in /libavformat/iamfdec.c. |
| CVE-2024-58253 | LOW | 2.9 | 0.1% | May 2, 2025 | In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to inva... |
| CVE-2024-11142 | HIGH | 8.8 | 0.2% | May 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forge... |
| CVE-2024-13860 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bbp_topic_title’ param... |
| CVE-2024-13859 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bp_nouveau_ajax_media_... |
| CVE-2024-13858 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | The BuddyBoss Platform plugin and BuddyBoss Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘in... |
| CVE-2024-13420 | MEDIUM | 4.3 | 0.2% | May 2, 2025 | Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a missing capability check on ... |
| CVE-2024-13419 | MEDIUM | 5.4 | 0.2% | May 2, 2025 | Multiple plugins and/or themes for WordPress using Smart Framework are vulnerable to Stored Cross-Site Scripting due to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now