2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45198 | HIGH | 8.8 | 0.5% | Apr 3, 2025 | insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters i... |
| CVE-2024-22611 | CRITICAL | 9.8 | 5.0% | Apr 3, 2025 | OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.cl... |
| CVE-2024-4877 | HIGH | 8.8 | 0.4% | Apr 3, 2025 | OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe whi... |
| CVE-2024-9416 | MEDIUM | 5.4 | 0.2% | Apr 3, 2025 | The Modula Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bundled Fanc... |
| CVE-2024-53868 | HIGH | 7.5 | 0.6% | Apr 3, 2025 | Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffi... |
| CVE-2024-13673 | MEDIUM | 6.4 | 0.3% | Apr 3, 2025 | The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' s... |
| CVE-2024-38392 | CRITICAL | 9.1 | 0.4% | Apr 2, 2025 | Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remo... |
| CVE-2024-37917 | HIGH | 7.5 | 0.4% | Apr 2, 2025 | Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (so... |
| CVE-2024-36337 | HIGH | 7.9 | 0.1% | Apr 2, 2025 | Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss ... |
| CVE-2024-36336 | HIGH | 7.9 | 0.1% | Apr 2, 2025 | Integer overflow within the AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to a... |
| CVE-2024-36328 | HIGH | 7.3 | 0.1% | Apr 2, 2025 | Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss ... |
| CVE-2024-56476 | MEDIUM | 5.3 | 0.3% | Apr 2, 2025 | IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login a... |
| CVE-2024-56475 | MEDIUM | 5.4 | 0.2% | Apr 2, 2025 | IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authent... |
| CVE-2024-56474 | HIGH | 8.8 | 0.2% | Apr 2, 2025 | IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker t... |
| CVE-2024-56341 | MEDIUM | 5.4 | 0.2% | Apr 2, 2025 | IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an auth... |
| CVE-2024-25051 | HIGH | 7.2 | 0.3% | Apr 2, 2025 | IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated p... |
| CVE-2024-50597 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50596 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50595 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50594 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRT... |
| CVE-2024-50385 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ... |
| CVE-2024-50384 | HIGH | 7.5 | 0.7% | Apr 2, 2025 | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZ... |
| CVE-2024-45064 | CRITICAL | 9.8 | 0.9% | Apr 2, 2025 | A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZ... |
| CVE-2024-13637 | MEDIUM | 6.5 | 0.3% | Apr 2, 2025 | The Demo Awesome plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2024-12410 | MEDIUM | 4.9 | 0.4% | Apr 2, 2025 | The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now