2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40864 | LOW | 2.7 | 0.6% | Mar 31, 2025 | The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequ... |
| CVE-2024-54809 | CRITICAL | 9.8 | 0.6% | Mar 31, 2025 | Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header fu... |
| CVE-2024-54808 | CRITICAL | 9.8 | 0.7% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionSe... |
| CVE-2024-54807 | CRITICAL | 9.8 | 2.2% | Mar 31, 2025 | In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exe... |
| CVE-2024-54806 | CRITICAL | 9.8 | 1.0% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execu... |
| CVE-2024-54805 | CRITICAL | 9.8 | 2.2% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque... |
| CVE-2024-54804 | CRITICAL | 9.8 | 1.6% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque... |
| CVE-2024-54803 | CRITICAL | 9.8 | 1.6% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque... |
| CVE-2024-54802 | CRITICAL | 9.8 | 0.6% | Mar 31, 2025 | In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow... |
| CVE-2024-24456 | MEDIUM | 5.9 | 0.3% | Mar 31, 2025 | An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentia... |
| CVE-2024-12021 | HIGH | 8.5 | 0.3% | Mar 31, 2025 | Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interf... |
| CVE-2024-55093 | MEDIUM | 4.7 | 0.2% | Mar 31, 2025 | phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts. |
| CVE-2024-13804 | CRITICAL | 9.8 | 0.4% | Mar 30, 2025 | Unauthenticated RCE in HPE Insight Cluster Management Utility |
| CVE-2024-55895 | MEDIUM | 5.3 | 0.3% | Mar 29, 2025 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec... |
| CVE-2024-11180 | MEDIUM | 5.4 | 0.2% | Mar 29, 2025 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Tim... |
| CVE-2024-13557 | MEDIUM | 6.5 | 0.3% | Mar 29, 2025 | The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t... |
| CVE-2024-7577 | HIGH | 7.5 | 0.3% | Mar 29, 2025 | IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation ... |
| CVE-2024-51477 | MEDIUM | 6.5 | 0.3% | Mar 29, 2025 | IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an... |
| CVE-2024-43186 | MEDIUM | 6.5 | 0.2% | Mar 29, 2025 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored ... |
| CVE-2024-58130 | MEDIUM | 6.1 | 0.2% | Mar 28, 2025 | In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization... |
| CVE-2024-58129 | MEDIUM | 4.8 | 0.2% | Mar 28, 2025 | In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and t... |
| CVE-2024-58128 | MEDIUM | 4.8 | 0.2% | Mar 28, 2025 | In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus a... |
| CVE-2024-23338 | — | — | — | Mar 28, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-53427. Reason: This candidate is a ... |
| CVE-2024-6875 | MEDIUM | 6.5 | 0.4% | Mar 28, 2025 | A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak ... |
| CVE-2024-57083 | HIGH | 7.5 | 0.5% | Mar 28, 2025 | A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attac... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now