2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32037 | MEDIUM | 5.3 | 0.4% | Feb 11, 2025 | GeoNetwork is a catalog application to manage spatially referenced resources. In versions prior to 4.2.10 and 4.4.5, the... |
| CVE-2024-12833 | MEDIUM | 6.1 | 0.8% | Feb 11, 2025 | Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows n... |
| CVE-2024-40586 | MEDIUM | 6.7 | 0.2% | Feb 11, 2025 | An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, versio... |
| CVE-2024-36508 | MEDIUM | 6 | 0.2% | Feb 11, 2025 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For... |
| CVE-2024-27780 | MEDIUM | 5.4 | 0.3% | Feb 11, 2025 | Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] i... |
| CVE-2024-12756 | MEDIUM | 6.1 | 0.3% | Feb 11, 2025 | An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of ... |
| CVE-2024-12755 | MEDIUM | 5.4 | 0.3% | Feb 11, 2025 | A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential di... |
| CVE-2024-13843 | MEDIUM | 4.4 | 0.3% | Feb 11, 2025 | Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before versio... |
| CVE-2024-13842 | MEDIUM | 4.4 | 0.3% | Feb 11, 2025 | A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows... |
| CVE-2024-13830 | MEDIUM | 6.1 | 0.6% | Feb 11, 2025 | Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a... |
| CVE-2024-12797 | MEDIUM | 6.3 | 2.4% | Feb 11, 2025 | Issue summary: Clients using RFC7250 Raw Public Keys (RPKs) to authenticate a server may fail to notice that the server ... |
| CVE-2024-12058 | MEDIUM | 4.9 | 0.9% | Feb 11, 2025 | External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version... |
| CVE-2024-11771 | MEDIUM | 5.3 | 0.9% | Feb 11, 2025 | Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted function... |
| CVE-2024-54090 | MEDIUM | 6 | 0.4% | Feb 11, 2025 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v... |
| CVE-2024-53651 | MEDIUM | 5.1 | 0.2% | Feb 11, 2025 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions),... |
| CVE-2024-23814 | MEDIUM | 6.9 | 0.6% | Feb 11, 2025 | The integrated ICMP service of the network stack of affected devices can be forced to exhaust its available memory reso... |
| CVE-2024-13506 | MEDIUM | 6.4 | 0.4% | Feb 11, 2025 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ... |
| CVE-2024-52612 | MEDIUM | 4.8 | 0.5% | Feb 11, 2025 | SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient ... |
| CVE-2024-45718 | MEDIUM | 4.6 | 0.2% | Feb 11, 2025 | Sensitive data could be exposed to non- privileged users in a configuration file. Local access to the computer with a l... |
| CVE-2024-28989 | MEDIUM | 5.5 | 0.3% | Feb 11, 2025 | SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive in... |
| CVE-2024-13570 | MEDIUM | 6.1 | 0.6% | Feb 11, 2025 | The Stray Random Quotes WordPress plugin through 1.9.9 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2024-13544 | MEDIUM | 4.8 | 0.3% | Feb 11, 2025 | The Zarinpal Paid Download WordPress plugin through 2.3 does not properly validate uploaded files, allowing high privile... |
| CVE-2024-13543 | MEDIUM | 6.1 | 0.6% | Feb 11, 2025 | The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2024-12599 | MEDIUM | 6.4 | 0.3% | Feb 11, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-57178 | MEDIUM | 5.9 | 0.2% | Feb 10, 2025 | An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' pa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now