2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56474 | HIGH | 8.8 | 0.2% | Apr 2, 2025 | IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker t... |
| CVE-2024-56341 | MEDIUM | 5.4 | 0.2% | Apr 2, 2025 | IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an auth... |
| CVE-2024-25051 | HIGH | 7.2 | 0.3% | Apr 2, 2025 | IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated p... |
| CVE-2024-50597 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50596 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50595 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50594 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50385 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ... |
| CVE-2024-50384 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ... |
| CVE-2024-45064 | CRITICAL | 9.8 | 0.9% | Apr 2, 2025 | A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZ... |
| CVE-2024-13637 | MEDIUM | 6.5 | 0.3% | Apr 2, 2025 | The Demo Awesome plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2024-12410 | MEDIUM | 4.9 | 0.4% | Apr 2, 2025 | The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versi... |
| CVE-2024-39780 | CRITICAL | 9.8 | 0.3% | Apr 2, 2025 | A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for g... |
| CVE-2024-45700 | MEDIUM | 6.5 | 0.3% | Apr 2, 2025 | Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send special... |
| CVE-2024-45699 | MEDIUM | 5.4 | 0.3% | Apr 2, 2025 | The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl param... |
| CVE-2024-42325 | LOW | 3.5 | 0.3% | Apr 2, 2025 | Zabbix API user.get returns all users that share common group with the calling user. This includes media and other infor... |
| CVE-2024-36469 | LOW | 3.1 | 0.3% | Apr 2, 2025 | Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one. |
| CVE-2024-36465 | HIGH | 8.8 | 23.0% | Apr 2, 2025 | A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiSer... |
| CVE-2024-13941 | MEDIUM | 5.3 | 0.2% | Apr 1, 2025 | A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ou... |
| CVE-2024-13553 | CRITICAL | 9.8 | 0.5% | Apr 1, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account t... |
| CVE-2024-56325 | CRITICAL | 9.8 | 78.2% | Apr 1, 2025 | Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Norm... |
| CVE-2024-12278 | MEDIUM | 6.1 | 0.3% | Apr 1, 2025 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typi... |
| CVE-2024-12189 | MEDIUM | 6.4 | 0.2% | Apr 1, 2025 | The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPres... |
| CVE-2024-13567 | HIGH | 7.5 | 0.6% | Apr 1, 2025 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Ex... |
| CVE-2024-54533 | HIGH | 7 | 0.6% | Mar 31, 2025 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now