2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53304 | MEDIUM | 6.5 | 0.3% | Apr 16, 2025 | An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and ... |
| CVE-2024-53303 | HIGH | 8.8 | 0.7% | Apr 16, 2025 | A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 al... |
| CVE-2024-40074 | MEDIUM | 4.8 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat... |
| CVE-2024-40073 | CRITICAL | 9.8 | 0.4% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template p... |
| CVE-2024-40072 | CRITICAL | 9.8 | 0.4% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2024-40071 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge... |
| CVE-2024-40070 | MEDIUM | 5.1 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge... |
| CVE-2024-40069 | MEDIUM | 5.4 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generat... |
| CVE-2024-40068 | MEDIUM | 5.9 | 0.2% | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2024-22314 | HIGH | 7.5 | 0.2% | Apr 16, 2025 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.12 uses weaker than expected cryptographic algorithms that c... |
| CVE-2024-58249 | LOW | 3.7 | 0.4% | Apr 16, 2025 | In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. |
| CVE-2024-56736 | MEDIUM | 6.5 | 0.5% | Apr 16, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating):... |
| CVE-2024-58097 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix RCU stall while reaping monitor d... |
| CVE-2024-58096 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: add srng->lock for ath11k_hal_srng_* ... |
| CVE-2024-58095 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before txBeginAnon() call ... |
| CVE-2024-58094 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: jfs: add check read-only before truncation in jfs_t... |
| CVE-2024-58093 | HIGH | 7.8 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix link state exit during switch upstrea... |
| CVE-2024-58248 | LOW | 3.5 | 0.3% | Apr 16, 2025 | nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate red... |
| CVE-2024-46915 | — | — | — | Apr 16, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-58092 | MEDIUM | 5.5 | 0.2% | Apr 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix legacy client tracking initialization Ge... |
| CVE-2024-52281 | HIGH | 8.9 | 0.5% | Apr 16, 2025 | A: Improper Neutralization of Input During Web Page Generation vulnerability in SUSE rancher allows a malicious actor to... |
| CVE-2024-22036 | CRITICAL | 9.1 | 0.7% | Apr 16, 2025 | A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail... |
| CVE-2024-10680 | MEDIUM | 4.8 | 0.2% | Apr 16, 2025 | The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-13452 | MEDIUM | 6.1 | 0.3% | Apr 16, 2025 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2024-49200 | MEDIUM | 6.4 | 0.3% | Apr 15, 2025 | An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential D... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now