2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46546 | HIGH | 7.3 | 0.4% | Apr 22, 2025 | NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formF... |
| CVE-2024-40446 | CRITICAL | 9.8 | 0.6% | Apr 22, 2025 | An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script |
| CVE-2024-40445 | HIGH | 7.3 | 0.6% | Apr 22, 2025 | A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read ... |
| CVE-2024-11299 | HIGH | 7.5 | 0.3% | Apr 22, 2025 | The Memberpress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2024-13569 | HIGH | 7.1 | 0.5% | Apr 22, 2025 | The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-46899 | HIGH | 7.1 | 0.3% | Apr 22, 2025 | Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentia... |
| CVE-2024-58250 | CRITICAL | 9.3 | 0.2% | Apr 22, 2025 | The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges. |
| CVE-2024-57394 | HIGH | 8.8 | 0.5% | Apr 21, 2025 | The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore ... |
| CVE-2024-12543 | MEDIUM | 5.9 | 0.3% | Apr 21, 2025 | User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows... |
| CVE-2024-42699 | MEDIUM | 6.5 | 0.3% | Apr 21, 2025 | Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to i... |
| CVE-2024-12863 | MEDIUM | 5.6 | 0.3% | Apr 21, 2025 | Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malic... |
| CVE-2024-12862 | MEDIUM | 5.5 | 0.2% | Apr 21, 2025 | Incorrect Authorization vulnerability in the OpenText Content Server REST API on Windows, Linux allows users without the... |
| CVE-2024-41446 | MEDIUM | 5.4 | 0.2% | Apr 21, 2025 | A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scr... |
| CVE-2024-13926 | HIGH | 7.5 | 0.4% | Apr 19, 2025 | The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post contain... |
| CVE-2024-53591 | CRITICAL | 9.8 | 0.5% | Apr 18, 2025 | An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack. |
| CVE-2024-57493 | MEDIUM | 5.5 | 0.2% | Apr 18, 2025 | An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the setsockop... |
| CVE-2024-41447 | MEDIUM | 5.4 | 0.2% | Apr 18, 2025 | A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scr... |
| CVE-2024-29643 | CRITICAL | 9.1 | 0.5% | Apr 18, 2025 | An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component. |
| CVE-2024-11421 | — | — | — | Apr 18, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: The developer has disputed this as a vulnerabili... |
| CVE-2024-46089 | MEDIUM | 6.3 | 0.5% | Apr 18, 2025 | 74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin. |
| CVE-2024-49808 | MEDIUM | 6.5 | 0.3% | Apr 18, 2025 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity... |
| CVE-2024-45651 | MEDIUM | 6.5 | 0.3% | Apr 18, 2025 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure w... |
| CVE-2024-26014 | — | — | — | Apr 18, 2025 | Rejected reason: Not used |
| CVE-2024-13650 | MEDIUM | 6.4 | 0.2% | Apr 18, 2025 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'PAFE Before ... |
| CVE-2024-42178 | HIGH | 7.5 | 0.2% | Apr 17, 2025 | HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthori... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now