2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42177 | MEDIUM | 6.4 | 0.1% | Apr 17, 2025 | HCL MyXalytics is affected by SSL∕TLS Protocol affected with BREACH & LUCKY13 vulnerabilities. Attackers can exploit the... |
| CVE-2024-55211 | HIGH | 8.4 | 0.2% | Apr 17, 2025 | An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie. |
| CVE-2024-53924 | CRITICAL | 9.8 | 0.8% | Apr 17, 2025 | Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell,... |
| CVE-2024-40124 | MEDIUM | 5.4 | 0.2% | Apr 17, 2025 | Pydio Core <= 8.2.5 is vulnerable to Cross Site Scripting (XSS) via the New URL Bookmark feature. |
| CVE-2024-56518 | CRITICAL | 9.8 | 0.8% | Apr 17, 2025 | Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelc... |
| CVE-2024-55238 | HIGH | 8.8 | 0.5% | Apr 17, 2025 | OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function l... |
| CVE-2024-12530 | HIGH | 7 | 0.2% | Apr 17, 2025 | Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.Thi... |
| CVE-2024-13925 | HIGH | 7.5 | 0.4% | Apr 17, 2025 | The Klarna Checkout for WooCommerce WordPress plugin before 2.13.5 exposes an unauthenticated WooCommerce Ajax endpoint ... |
| CVE-2024-11924 | LOW | 3.5 | 0.2% | Apr 17, 2025 | The Icegram Express formerly known as Email Subscribers WordPress plugin before 5.7.52 does not sanitise and escape som... |
| CVE-2024-55372 | CRITICAL | 9.8 | 0.5% | Apr 16, 2025 | Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to ... |
| CVE-2024-55371 | CRITICAL | 9.8 | 0.5% | Apr 16, 2025 | Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to res... |
| CVE-2024-53305 | HIGH | 7.3 | 0.5% | Apr 16, 2025 | An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supp... |
| CVE-2024-53304 | MEDIUM | 6.5 | 0.3% | Apr 16, 2025 | An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and ... |
| CVE-2024-53303 | HIGH | 8.8 | 0.7% | Apr 16, 2025 | A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 al... |
| CVE-2024-40074 | MEDIUM | 4.8 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat... |
| CVE-2024-40073 | CRITICAL | 9.8 | 0.4% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template p... |
| CVE-2024-40072 | CRITICAL | 9.8 | 0.4% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2024-40071 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge... |
| CVE-2024-40070 | MEDIUM | 5.1 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge... |
| CVE-2024-40069 | MEDIUM | 5.4 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat... |
| CVE-2024-40068 | MEDIUM | 5.9 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2024-22314 | HIGH | 7.5 | 0.2% | Apr 16, 2025 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that c... |
| CVE-2024-58249 | LOW | 3.7 | 0.4% | Apr 16, 2025 | In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. |
| CVE-2024-56736 | MEDIUM | 6.5 | 0.5% | Apr 16, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating):... |
| CVE-2024-58097 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix RCU stall while reaping monitor d... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now