2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39780 | CRITICAL | 9.8 | 0.3% | Apr 2, 2025 | A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for g... |
| CVE-2024-45700 | MEDIUM | 6.5 | 0.3% | Apr 2, 2025 | Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send special... |
| CVE-2024-45699 | MEDIUM | 5.4 | 0.3% | Apr 2, 2025 | The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl param... |
| CVE-2024-42325 | LOW | 3.5 | 0.3% | Apr 2, 2025 | Zabbix API user.get returns all users that share common group with the calling user. This includes media and other infor... |
| CVE-2024-36469 | LOW | 3.1 | 0.3% | Apr 2, 2025 | Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one. |
| CVE-2024-36465 | HIGH | 8.8 | 23.0% | Apr 2, 2025 | A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiSer... |
| CVE-2024-13941 | MEDIUM | 5.3 | 0.2% | Apr 1, 2025 | A vulnerability was found in ouch-org ouch up to 0.3.1. It has been classified as critical. This affects the function ou... |
| CVE-2024-13553 | CRITICAL | 9.8 | 0.5% | Apr 1, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account t... |
| CVE-2024-56325 | CRITICAL | 9.8 | 78.2% | Apr 1, 2025 | Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Norm... |
| CVE-2024-12278 | MEDIUM | 6.1 | 0.3% | Apr 1, 2025 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typi... |
| CVE-2024-12189 | MEDIUM | 6.4 | 0.2% | Apr 1, 2025 | The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPres... |
| CVE-2024-13567 | HIGH | 7.5 | 0.6% | Apr 1, 2025 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Ex... |
| CVE-2024-54533 | HIGH | 7 | 0.6% | Mar 31, 2025 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS... |
| CVE-2024-40864 | LOW | 2.7 | 0.6% | Mar 31, 2025 | The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequ... |
| CVE-2024-54809 | CRITICAL | 9.8 | 0.6% | Mar 31, 2025 | Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header fu... |
| CVE-2024-54808 | CRITICAL | 9.8 | 0.7% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionSe... |
| CVE-2024-54807 | CRITICAL | 9.8 | 2.2% | Mar 31, 2025 | In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exe... |
| CVE-2024-54806 | CRITICAL | 9.8 | 1.0% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execu... |
| CVE-2024-54805 | CRITICAL | 9.8 | 2.2% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque... |
| CVE-2024-54804 | CRITICAL | 9.8 | 1.6% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque... |
| CVE-2024-54803 | CRITICAL | 9.8 | 1.6% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque... |
| CVE-2024-54802 | CRITICAL | 9.8 | 0.6% | Mar 31, 2025 | In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow... |
| CVE-2024-24456 | MEDIUM | 5.9 | 0.3% | Mar 31, 2025 | An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentia... |
| CVE-2024-12021 | HIGH | 8.5 | 0.3% | Mar 31, 2025 | Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interf... |
| CVE-2024-55093 | MEDIUM | 4.7 | 0.2% | Mar 31, 2025 | phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now