2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57908 | HIGH | 7.1 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: imu: kmx61: fix information leak in triggered ... |
| CVE-2024-57907 | HIGH | 7.1 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: adc: rockchip_saradc: fix information leak in ... |
| CVE-2024-57906 | HIGH | 7.1 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads8688: fix information leak in trigg... |
| CVE-2024-57905 | HIGH | 7.1 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1119: fix information leak in trigg... |
| CVE-2024-57904 | HIGH | 7.8 | 0.2% | Jan 19, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91: call input_free_device() on allocat... |
| CVE-2024-45652 | HIGH | 7.5 | 0.8% | Jan 19, 2025 | IBM Maximo MXAPIASSET API 7.6.1.3 could allow a remote attacker to traverse directories on the system. An attacker could... |
| CVE-2024-45662 | HIGH | 7.5 | 0.6% | Jan 18, 2025 | IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a rem... |
| CVE-2024-49354 | HIGH | 7.5 | 0.3% | Jan 18, 2025 | IBM Concert 1.0.0, 1.0.1, and 1.0.2 is vulnerable to sensitive information disclosure through specially crafted API Call... |
| CVE-2024-47106 | HIGH | 7.5 | 0.4% | Jan 18, 2025 | IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain sensitive information fro... |
| CVE-2024-13184 | HIGH | 7.5 | 0.5% | Jan 18, 2025 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the ... |
| CVE-2024-57030 | HIGH | 8.1 | 0.6% | Jan 17, 2025 | Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter. |
| CVE-2024-52870 | HIGH | 7.1 | 0.2% | Jan 17, 2025 | Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unin... |
| CVE-2024-12757 | HIGH | 8.8 | 0.5% | Jan 17, 2025 | Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker ... |
| CVE-2024-26155 | HIGH | 8.6 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal.... |
| CVE-2024-26153 | HIGH | 7.4 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (C... |
| CVE-2024-12703 | HIGH | 8.5 | 0.3% | Jan 17, 2025 | CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an... |
| CVE-2024-12142 | HIGH | 8.8 | 0.3% | Jan 17, 2025 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information di... |
| CVE-2024-10497 | HIGH | 8.8 | 0.5% | Jan 17, 2025 | CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker t... |
| CVE-2024-13377 | HIGH | 7.2 | 0.3% | Jan 17, 2025 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versi... |
| CVE-2024-12476 | HIGH | 8.4 | 0.3% | Jan 17, 2025 | CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclos... |
| CVE-2024-12399 | HIGH | 7.1 | 0.2% | Jan 17, 2025 | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t... |
| CVE-2024-11425 | HIGH | 8.7 | 0.6% | Jan 17, 2025 | CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product whe... |
| CVE-2024-13333 | HIGH | 7.5 | 0.9% | Jan 17, 2025 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2024-52363 | HIGH | 7.5 | 0.6% | Jan 17, 2025 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker ... |
| CVE-2024-34579 | HIGH | 8.5 | 0.3% | Jan 17, 2025 | Fuji Electric Alpha5 SMART is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now