2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55577 | HIGH | 7 | 0.3% | Jan 15, 2025 | Stack-based buffer overflow vulnerability exists in Linux Ratfor 1.06 and earlier. When the software processes a file wh... |
| CVE-2024-57767 | HIGH | 8.6 | 0.4% | Jan 15, 2025 | MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download. |
| CVE-2024-57765 | HIGH | 7.5 | 0.4% | Jan 15, 2025 | MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list. |
| CVE-2024-57762 | HIGH | 7.5 | 0.5% | Jan 15, 2025 | MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file. |
| CVE-2024-57761 | HIGH | 8.1 | 0.5% | Jan 15, 2025 | An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execut... |
| CVE-2024-57757 | HIGH | 7.5 | 0.4% | Jan 15, 2025 | JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.c... |
| CVE-2024-54730 | HIGH | 7.5 | 0.5% | Jan 14, 2025 | Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function. |
| CVE-2024-42911 | HIGH | 7.4 | 0.6% | Jan 14, 2025 | ECOVACS Robotics Deebot T20 OMNI and T20e OMNI before 1.24.0 was discovered to contain a WiFi Remote Code Execution vuln... |
| CVE-2024-50858 | HIGH | 8.8 | 1.7% | Jan 14, 2025 | Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actio... |
| CVE-2024-55924 | HIGH | 8 | 0.3% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55921 | HIGH | 8.8 | 0.4% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-53263 | HIGH | 8.5 | 1.0% | Jan 14, 2025 | Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote host, it ... |
| CVE-2024-48858 | HIGH | 7.5 | 0.6% | Jan 14, 2025 | Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated att... |
| CVE-2024-56374 | HIGH | 7.5 | 1.9% | Jan 14, 2025 | An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit ... |
| CVE-2024-52006 | HIGH | 7.5 | 1.0% | Jan 14, 2025 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-... |
| CVE-2024-50338 | HIGH | 7.4 | 3.1% | Jan 14, 2025 | Git Credential Manager (GCM) is a secure Git credential helper built on .NET that runs on Windows, macOS, and Linux. The... |
| CVE-2024-48857 | HIGH | 7.5 | 0.4% | Jan 14, 2025 | NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated atta... |
| CVE-2024-48855 | HIGH | 7.5 | 0.4% | Jan 14, 2025 | Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ... |
| CVE-2024-48854 | HIGH | 7.5 | 0.4% | Jan 14, 2025 | Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to... |
| CVE-2024-13172 | HIGH | 7.8 | 0.5% | Jan 14, 2025 | Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Sec... |
| CVE-2024-13171 | HIGH | 7.8 | 17.6% | Jan 14, 2025 | Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Se... |
| CVE-2024-13170 | HIGH | 7.5 | 2.2% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13169 | HIGH | 7.8 | 0.4% | Jan 14, 2025 | An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upda... |
| CVE-2024-13168 | HIGH | 7.5 | 2.1% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13167 | HIGH | 7.5 | 2.1% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now