2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13593 | HIGH | 8.8 | 0.7% | Jan 23, 2025 | The BMLT Meeting Map plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.... |
| CVE-2024-12957 | HIGH | 8.4 | 0.2% | Jan 23, 2025 | A file handling command vulnerability in certain versions of Armoury Crate may result in arbitrary file deletion. Refer ... |
| CVE-2024-57722 | HIGH | 7.5 | 0.4% | Jan 23, 2025 | lunasvg v3.0.0 was discovered to contain a allocation-size-too-big bug via the component plutovg_surface_create. |
| CVE-2024-56924 | HIGH | 7.3 | 0.4% | Jan 22, 2025 | A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to... |
| CVE-2024-11166 | HIGH | 7.1 | 0.3% | Jan 22, 2025 | For TCAS II systems using transponders compliant with MOPS earlier than RTCA DO-181F, an attacker can impersonate a grou... |
| CVE-2024-55957 | HIGH | 7.8 | 0.2% | Jan 22, 2025 | In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 ... |
| CVE-2024-31903 | HIGH | 8.8 | 1.0% | Jan 22, 2025 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on th... |
| CVE-2024-24429 | HIGH | 8.6 | 0.5% | Jan 22, 2025 | A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of ... |
| CVE-2024-34235 | HIGH | 8.6 | 0.8% | Jan 22, 2025 | Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the... |
| CVE-2024-24430 | HIGH | 7.5 | 0.8% | Jan 22, 2025 | A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Serv... |
| CVE-2024-13499 | HIGH | 7.3 | 0.6% | Jan 22, 2025 | The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress... |
| CVE-2024-13496 | HIGH | 7.5 | 2.2% | Jan 22, 2025 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ... |
| CVE-2024-13495 | HIGH | 7.3 | 0.5% | Jan 22, 2025 | The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress... |
| CVE-2024-13361 | HIGH | 8.8 | 0.3% | Jan 22, 2025 | The AI Power: Complete AI Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability che... |
| CVE-2024-11218 | HIGH | 8.6 | 0.4% | Jan 22, 2025 | A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 a... |
| CVE-2024-49749 | HIGH | 8.8 | 0.2% | Jan 21, 2025 | In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remot... |
| CVE-2024-49745 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to ... |
| CVE-2024-49744 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mit... |
| CVE-2024-49742 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification ac... |
| CVE-2024-49738 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege... |
| CVE-2024-49737 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities ... |
| CVE-2024-49735 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This coul... |
| CVE-2024-49734 | HIGH | 7.5 | 0.3% | Jan 21, 2025 | In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a devic... |
| CVE-2024-49732 | HIGH | 7.8 | 0.1% | Jan 21, 2025 | In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user c... |
| CVE-2024-49724 | HIGH | 7 | 0.1% | Jan 21, 2025 | In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now