2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24451 | HIGH | 7.5 | 1.0% | Jan 21, 2025 | A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2... |
| CVE-2024-24444 | HIGH | 7.5 | 0.4% | Jan 21, 2025 | Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows... |
| CVE-2024-24442 | HIGH | 7.5 | 0.4% | Jan 21, 2025 | A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.... |
| CVE-2024-57542 | HIGH | 8.8 | 1.7% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_bt... |
| CVE-2024-57539 | HIGH | 8.2 | 1.3% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail. |
| CVE-2024-57536 | HIGH | 8 | 1.4% | Jan 21, 2025 | Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status. |
| CVE-2024-57036 | HIGH | 8.1 | 0.5% | Jan 21, 2025 | TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main f... |
| CVE-2024-53829 | HIGH | 8.2 | 0.2% | Jan 21, 2025 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ... |
| CVE-2024-49700 | HIGH | 7.1 | 0.3% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems ... |
| CVE-2024-49699 | HIGH | 8.8 | 0.8% | Jan 21, 2025 | Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue ... |
| CVE-2024-49666 | HIGH | 8.5 | 0.4% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ... |
| CVE-2024-49333 | HIGH | 8.5 | 0.4% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega... |
| CVE-2024-49303 | HIGH | 8.5 | 0.4% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega... |
| CVE-2024-49300 | HIGH | 7.1 | 0.3% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Hero Mega... |
| CVE-2024-57945 | HIGH | 7.1 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Fix the out of bound issue of vmemmap ad... |
| CVE-2024-57943 | HIGH | 7.8 | 0.2% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix the new buffer was not zeroed before wri... |
| CVE-2024-43709 | HIGH | 7.5 | 0.6% | Jan 21, 2025 | An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resul... |
| CVE-2024-12104 | HIGH | 7.5 | 0.3% | Jan 21, 2025 | The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthori... |
| CVE-2024-10936 | HIGH | 8.8 | 1.1% | Jan 21, 2025 | The String locator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.... |
| CVE-2024-22348 | HIGH | 7.5 | 0.4% | Jan 20, 2025 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) whi... |
| CVE-2024-22347 | HIGH | 7.5 | 0.3% | Jan 20, 2025 | IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algor... |
| CVE-2024-51738 | HIGH | 8.1 | 0.6% | Jan 20, 2025 | Sunshine is a self-hosted game stream host for Moonlight. In 0.23.1 and earlier, Sunshine's pairing protocol implementat... |
| CVE-2024-41743 | HIGH | 7.5 | 0.6% | Jan 19, 2025 | IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connect... |
| CVE-2024-41742 | HIGH | 7.5 | 0.7% | Jan 19, 2025 | IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout... |
| CVE-2024-57929 | HIGH | 7.1 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: dm array: fix releasing a faulty array block twice ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now