2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-58106 | HIGH | 7.5 | 0.2% | Apr 7, 2025 | Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail... |
| CVE-2024-58133 | MEDIUM | 4 | 0.2% | Apr 6, 2025 | In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarti... |
| CVE-2024-58132 | MEDIUM | 4 | 0.2% | Apr 6, 2025 | In chainmaker-go (aka ChainMaker) before 2.3.6, multiple updates to a single node's configuration can cause other normal... |
| CVE-2024-58131 | LOW | 3.7 | 0.2% | Apr 6, 2025 | FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a ma... |
| CVE-2024-56370 | MEDIUM | 6.5 | 0.3% | Apr 5, 2025 | Net::Xero 0.044 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograph... |
| CVE-2024-52322 | MEDIUM | 5.5 | 0.3% | Apr 5, 2025 | WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt... |
| CVE-2024-58036 | MEDIUM | 5.5 | 0.2% | Apr 5, 2025 | Net::Dropbox::API 1.9 and earlier for Perl uses the rand() function as the default source of entropy, which is not crypt... |
| CVE-2024-57868 | MEDIUM | 5.5 | 0.3% | Apr 5, 2025 | Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographica... |
| CVE-2024-57835 | MEDIUM | 5.5 | 0.2% | Apr 5, 2025 | Amon2::Auth::Site::LINE uses the String::Random module to generate nonce values. String::Random defaults to Perl's bui... |
| CVE-2024-13776 | HIGH | 8.1 | 0.3% | Apr 5, 2025 | The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modificati... |
| CVE-2024-13604 | HIGH | 7.5 | 0.4% | Apr 5, 2025 | The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to ... |
| CVE-2024-11235 | HIGH | 8.1 | 1.3% | Apr 4, 2025 | In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??= operator and... |
| CVE-2024-51800 | CRITICAL | 9.8 | 0.4% | Apr 4, 2025 | Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: f... |
| CVE-2024-42208 | LOW | 3.5 | 0.2% | Apr 4, 2025 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in... |
| CVE-2024-13898 | MEDIUM | 4.4 | 0.2% | Apr 4, 2025 | The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website pl... |
| CVE-2024-13708 | HIGH | 7.2 | 0.2% | Apr 4, 2025 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ve... |
| CVE-2024-13645 | CRITICAL | 9.8 | 0.6% | Apr 4, 2025 | The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including,... |
| CVE-2024-13744 | CRITICAL | 9.8 | 0.6% | Apr 4, 2025 | The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida... |
| CVE-2024-56528 | HIGH | 7.5 | 0.4% | Apr 3, 2025 | This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establish... |
| CVE-2024-47217 | MEDIUM | 6.5 | 0.3% | Apr 3, 2025 | An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated ... |
| CVE-2024-47215 | HIGH | 7.5 | 0.4% | Apr 3, 2025 | An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an in... |
| CVE-2024-47214 | HIGH | 7.5 | 0.4% | Apr 3, 2025 | An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind ... |
| CVE-2024-47213 | HIGH | 7.5 | 0.4% | Apr 3, 2025 | An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to th... |
| CVE-2024-47212 | HIGH | 7.5 | 0.4% | Apr 3, 2025 | An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API end... |
| CVE-2024-45199 | HIGH | 8.8 | 0.5% | Apr 3, 2025 | insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious param... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now