2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41198 | CRITICAL | 9.8 | 0.5% | May 22, 2025 | An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges... |
| CVE-2024-41197 | CRITICAL | 9.8 | 0.5% | May 22, 2025 | An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privilege... |
| CVE-2024-41196 | CRITICAL | 9.8 | 0.6% | May 22, 2025 | An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privi... |
| CVE-2024-41195 | CRITICAL | 9.8 | 0.5% | May 22, 2025 | An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate ... |
| CVE-2024-13955 | CRITICAL | 9.4 | 0.3% | May 22, 2025 | 2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if a... |
| CVE-2024-48853 | CRITICAL | 9.5 | 0.3% | May 22, 2025 | An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a... |
| CVE-2024-8673 | CRITICAL | 9.1 | 1.6% | May 15, 2025 | The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of S... |
| CVE-2024-6809 | CRITICAL | 9.8 | 0.6% | May 15, 2025 | The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using ... |
| CVE-2024-6584 | CRITICAL | 9.1 | 0.5% | May 15, 2025 | The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs. |
| CVE-2024-6159 | CRITICAL | 9.8 | 2.5% | May 15, 2025 | The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a para... |
| CVE-2024-10865 | CRITICAL | 9.4 | 0.4% | May 14, 2025 | Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This i... |
| CVE-2024-24780 | CRITICAL | 9.8 | 1.3% | May 14, 2025 | Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create ... |
| CVE-2024-46506 | CRITICAL | 10 | 50.2% | May 13, 2025 | NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun... |
| CVE-2024-56524 | CRITICAL | 9.1 | 0.5% | May 12, 2025 | Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by add... |
| CVE-2024-56523 | CRITICAL | 9.1 | 0.5% | May 12, 2025 | Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by pla... |
| CVE-2024-12442 | CRITICAL | 9.8 | 1.1% | May 9, 2025 | EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote s... |
| CVE-2024-11861 | CRITICAL | 9.8 | 1.4% | May 9, 2025 | EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access. |
| CVE-2024-11617 | CRITICAL | 9.8 | 1.2% | May 9, 2025 | The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t... |
| CVE-2024-12378 | CRITICAL | 9.1 | 0.4% | May 8, 2025 | On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in pac... |
| CVE-2024-11186 | CRITICAL | 10 | 0.6% | May 8, 2025 | On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to ... |
| CVE-2024-12225 | CRITICAL | 9.1 | 0.3% | May 6, 2025 | A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes defa... |
| CVE-2024-49846 | CRITICAL | 9.1 | 0.2% | May 6, 2025 | Memory corruption while decoding of OTA messages from T3448 IE. |
| CVE-2024-57235 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface pa... |
| CVE-2024-57234 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p... |
| CVE-2024-57233 | CRITICAL | 9.8 | 1.2% | May 5, 2025 | NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface pa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now