2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58136 | CRITICAL | 9.8 | 87.7% | Apr 10, 2025 | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres... |
| CVE-2024-55210 | CRITICAL | 9.8 | 0.5% | Apr 9, 2025 | An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via ... |
| CVE-2024-8243 | MEDIUM | 6.3 | 0.1% | Apr 9, 2025 | The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and i... |
| CVE-2024-6860 | MEDIUM | 4.3 | 0.2% | Apr 9, 2025 | The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix setting... |
| CVE-2024-6857 | MEDIUM | 4.3 | 0.2% | Apr 9, 2025 | The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body ... |
| CVE-2024-55354 | HIGH | 8.8 | 0.1% | Apr 8, 2025 | Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a prot... |
| CVE-2024-12556 | CRITICAL | 9.8 | 0.4% | Apr 8, 2025 | Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal. |
| CVE-2024-52981 | HIGH | 7.5 | 0.5% | Apr 8, 2025 | An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested ... |
| CVE-2024-52980 | MEDIUM | 6.5 | 0.4% | Apr 8, 2025 | A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the ... |
| CVE-2024-52974 | MEDIUM | 6.5 | 0.3% | Apr 8, 2025 | An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana serve... |
| CVE-2024-48887 | CRITICAL | 9.8 | 11.3% | Apr 8, 2025 | A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to c... |
| CVE-2024-54025 | MEDIUM | 6.7 | 0.4% | Apr 8, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-54024 | HIGH | 7.2 | 1.1% | Apr 8, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-52962 | MEDIUM | 5.3 | 0.4% | Apr 8, 2025 | An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4... |
| CVE-2024-50565 | HIGH | 7.5 | 0.3% | Apr 8, 2025 | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS versio... |
| CVE-2024-46671 | HIGH | 7.2 | 0.4% | Apr 8, 2025 | An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, versi... |
| CVE-2024-32122 | MEDIUM | 4.4 | 0.2% | Apr 8, 2025 | A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7... |
| CVE-2024-26013 | HIGH | 7.5 | 0.4% | Apr 8, 2025 | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS versio... |
| CVE-2024-54092 | CRITICAL | 9.8 | 0.7% | Apr 8, 2025 | A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device K... |
| CVE-2024-41796 | MEDIUM | 6.9 | 0.3% | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de... |
| CVE-2024-41795 | MEDIUM | 6.9 | 0.2% | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de... |
| CVE-2024-41794 | CRITICAL | 9.8 | 0.5% | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcod... |
| CVE-2024-41793 | HIGH | 7.5 | 0.5% | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de... |
| CVE-2024-41792 | HIGH | 7.5 | 0.5% | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de... |
| CVE-2024-41791 | MEDIUM | 6.5 | 0.3% | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now