2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13943 | HIGH | 7.8 | 0.1% | Apr 30, 2025 | Tesla Model S Iris Modem QCMAP_ConnectionManager Improper Input Validation Sandbox Escape Vulnerability. This vulnerabil... |
| CVE-2024-9877 | MEDIUM | 5.3 | 0.2% | Apr 30, 2025 | : Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue af... |
| CVE-2024-9876 | HIGH | 8.5 | 0.2% | Apr 30, 2025 | : Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC... |
| CVE-2024-47784 | LOW | 2.6 | 0.2% | Apr 30, 2025 | Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in th... |
| CVE-2024-57698 | HIGH | 7.5 | 0.3% | Apr 29, 2025 | An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes with... |
| CVE-2024-58099 | MEDIUM | 5.5 | 0.2% | Apr 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_... |
| CVE-2024-12273 | LOW | 3.5 | 0.2% | Apr 29, 2025 | The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could... |
| CVE-2024-11922 | MEDIUM | 5.4 | 0.2% | Apr 28, 2025 | Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an a... |
| CVE-2024-10635 | MEDIUM | 5.3 | 0.2% | Apr 28, 2025 | Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthent... |
| CVE-2024-12706 | LOW | 2.1 | 0.2% | Apr 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital ... |
| CVE-2024-32499 | CRITICAL | 9.8 | 0.4% | Apr 28, 2025 | Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed. |
| CVE-2024-9771 | LOW | 3.5 | 0.2% | Apr 28, 2025 | The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-13688 | MEDIUM | 5.3 | 0.3% | Apr 28, 2025 | The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protectio... |
| CVE-2024-52888 | MEDIUM | 5.4 | 0.2% | Apr 27, 2025 | For an authenticated end-user the portal may run a script while attempting to display a directory or some file's propert... |
| CVE-2024-52887 | MEDIUM | 5.4 | 0.2% | Apr 27, 2025 | Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing... |
| CVE-2024-53636 | CRITICAL | 9.8 | 1.2% | Apr 26, 2025 | An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.... |
| CVE-2024-13812 | MEDIUM | 6.5 | 0.3% | Apr 26, 2025 | The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and... |
| CVE-2024-13808 | HIGH | 8.8 | 0.6% | Apr 26, 2025 | The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i... |
| CVE-2024-30152 | CRITICAL | 9.8 | 0.2% | Apr 25, 2025 | HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain acce... |
| CVE-2024-56156 | CRITICAL | 9 | 0.6% | Apr 25, 2025 | Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypa... |
| CVE-2024-57375 | LOW | 2.4 | 0.2% | Apr 25, 2025 | Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to c... |
| CVE-2024-6199 | HIGH | 7.7 | 0.2% | Apr 25, 2025 | An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS ... |
| CVE-2024-6198 | HIGH | 7.7 | 0.3% | Apr 25, 2025 | The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the ... |
| CVE-2024-11917 | HIGH | 8.1 | 0.4% | Apr 25, 2025 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includ... |
| CVE-2024-30127 | LOW | 3.2 | 0.1% | Apr 24, 2025 | Missing "no cache" headers in HCL Leap permits sensitive data to be cached. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now