2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36280 | MEDIUM | 6.7 | 0.2% | Feb 12, 2025 | Uncontrolled search path for some Intel(R) High Level Synthesis Compiler software before version 24.2 may allow an authe... |
| CVE-2024-32942 | MEDIUM | 6.7 | 0.2% | Feb 12, 2025 | Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenti... |
| CVE-2024-32938 | MEDIUM | 6.7 | 0.2% | Feb 12, 2025 | Uncontrolled search path for some Intel(R) MPI Library for Windows software before version 2021.13 may allow an authenti... |
| CVE-2024-31157 | MEDIUM | 6.8 | 0.2% | Feb 12, 2025 | Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to ... |
| CVE-2024-31153 | MEDIUM | 5.5 | 0.2% | Feb 12, 2025 | Improper input validation for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authentica... |
| CVE-2024-31068 | MEDIUM | 5.6 | 0.2% | Feb 12, 2025 | Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potent... |
| CVE-2024-30211 | MEDIUM | 6 | 0.2% | Feb 12, 2025 | Improper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authent... |
| CVE-2024-28047 | MEDIUM | 6.8 | 0.2% | Feb 12, 2025 | Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl... |
| CVE-2024-26021 | MEDIUM | 4.6 | 0.2% | Feb 12, 2025 | Improper initialization in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged... |
| CVE-2024-25571 | MEDIUM | 4.6 | 0.2% | Feb 12, 2025 | Improper input validation in some Intel(R) SPS firmware before SPS_E5_06.01.04.059.0 may allow a privileged user to pote... |
| CVE-2024-24852 | MEDIUM | 6.7 | 0.2% | Feb 12, 2025 | Uncontrolled search path in some Intel(R) Ethernet Adapter Complete Driver Pack install before versions 29.1 may allow a... |
| CVE-2024-21859 | MEDIUM | 6.8 | 0.2% | Feb 12, 2025 | Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentiall... |
| CVE-2024-21830 | MEDIUM | 6.7 | 0.2% | Feb 12, 2025 | Uncontrolled search path in some Intel(R) VPL software before version 2023.4.0 may allow an authenticated user to potent... |
| CVE-2024-6097 | MEDIUM | 5.3 | 0.5% | Feb 12, 2025 | In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local t... |
| CVE-2024-11629 | MEDIUM | 6.5 | 0.4% | Feb 12, 2025 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, th... |
| CVE-2024-54160 | MEDIUM | 6.4 | 0.6% | Feb 12, 2025 | dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because ... |
| CVE-2024-12379 | MEDIUM | 6.5 | 0.5% | Feb 12, 2025 | A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4... |
| CVE-2024-57952 | MEDIUM | 5.5 | 0.2% | Feb 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: Revert "libfs: fix infinite directory reads for off... |
| CVE-2024-23563 | MEDIUM | 4.4 | 0.1% | Feb 12, 2025 | HCL Connections Docs is vulnerable to a sensitive information disclosure which could allow a user to obtain sensitive in... |
| CVE-2024-10322 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads... |
| CVE-2024-12386 | MEDIUM | 5.4 | 0.2% | Feb 12, 2025 | The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-13459 | MEDIUM | 5.4 | 0.3% | Feb 12, 2025 | The FuseDesk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusedesk_newcase' short... |
| CVE-2024-13456 | MEDIUM | 5.4 | 0.2% | Feb 12, 2025 | The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wqt-question' sh... |
| CVE-2024-13437 | MEDIUM | 4.3 | 0.2% | Feb 12, 2025 | The Book a Room plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2024-13821 | MEDIUM | 5.3 | 0.4% | Feb 12, 2025 | The WP Booking Calendar plugin for WordPress is vulnerable to Unauthenticated Post-Confirmation Booking Manipulation in ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now