2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57704 | HIGH | 8.8 | 0.4% | Jan 16, 2025 | Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi... |
| CVE-2024-55511 | HIGH | 7.8 | 0.3% | Jan 16, 2025 | A null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system ... |
| CVE-2024-54660 | HIGH | 8.7 | 0.5% | Jan 16, 2025 | A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala be... |
| CVE-2024-46450 | HIGH | 8.1 | 0.3% | Jan 16, 2025 | Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attacke... |
| CVE-2024-57578 | HIGH | 8.8 | 0.5% | Jan 16, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm functio... |
| CVE-2024-55954 | HIGH | 8.7 | 0.5% | Jan 16, 2025 | OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/use... |
| CVE-2024-52791 | HIGH | 7.5 | 0.7% | Jan 16, 2025 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to oth... |
| CVE-2024-36403 | HIGH | 7.5 | 0.7% | Jan 16, 2025 | Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 ... |
| CVE-2024-57775 | HIGH | 8.8 | 0.6% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?ins... |
| CVE-2024-57770 | HIGH | 8.8 | 0.6% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContr... |
| CVE-2024-57769 | HIGH | 8.8 | 0.6% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listDa... |
| CVE-2024-50633 | HIGH | 7.5 | 0.6% | Jan 16, 2025 | A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by... |
| CVE-2024-57162 | HIGH | 7.2 | 0.5% | Jan 16, 2025 | Campcodes Cybercafe Management System v1.0 is vulnerable to SQL Injection in /ccms/view-user-detail.php. |
| CVE-2024-12613 | HIGH | 7.5 | 0.5% | Jan 16, 2025 | The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fu... |
| CVE-2024-45331 | HIGH | 7.8 | 0.2% | Jan 16, 2025 | A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 throug... |
| CVE-2024-57728 | HIGH | 7.2 | 7.5% | Jan 15, 2025 | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file s... |
| CVE-2024-57727 | HIGH | 7.5 | 95.2% | Jan 15, 2025 | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enabl... |
| CVE-2024-48125 | HIGH | 7.5 | 0.4% | Jan 15, 2025 | An issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via craft... |
| CVE-2024-48123 | HIGH | 8.4 | 0.2% | Jan 15, 2025 | An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via u... |
| CVE-2024-40771 | HIGH | 7.8 | 0.2% | Jan 15, 2025 | The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and... |
| CVE-2024-27856 | HIGH | 7.8 | 0.6% | Jan 15, 2025 | The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5... |
| CVE-2024-52005 | HIGH | 8.8 | 0.5% | Jan 15, 2025 | Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messa... |
| CVE-2024-7085 | HIGH | 8.2 | 0.4% | Jan 15, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ S... |
| CVE-2024-57022 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" ... |
| CVE-2024-57021 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now