2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48944 | MEDIUM | 6.5 | 0.6% | Mar 27, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a reques... |
| CVE-2024-9773 | HIGH | 8 | 0.2% | Mar 27, 2025 | An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from... |
| CVE-2024-45361 | MEDIUM | 6.5 | 0.2% | Mar 27, 2025 | A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation... |
| CVE-2024-45356 | HIGH | 7.3 | 0.1% | Mar 27, 2025 | A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida... |
| CVE-2024-45355 | MEDIUM | 5.5 | 0.1% | Mar 27, 2025 | A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida... |
| CVE-2024-45354 | MEDIUM | 4.3 | 0.2% | Mar 27, 2025 | A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper inp... |
| CVE-2024-45353 | MEDIUM | 4.3 | 0.1% | Mar 27, 2025 | An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is ca... |
| CVE-2024-45352 | HIGH | 8.8 | 0.3% | Mar 27, 2025 | An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by impro... |
| CVE-2024-55965 | MEDIUM | 6.5 | 0.4% | Mar 26, 2025 | An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development in... |
| CVE-2024-55964 | CRITICAL | 9.8 | 6.3% | Mar 26, 2025 | An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea... |
| CVE-2024-55963 | MEDIUM | 6.5 | 27.7% | Mar 26, 2025 | An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the ... |
| CVE-2024-41643 | MEDIUM | 6.8 | 0.3% | Mar 26, 2025 | An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell log... |
| CVE-2024-45351 | HIGH | 7.8 | 0.2% | Mar 26, 2025 | A code execution vulnerability exists in the Xiaomi Game center application product. The vulnerability is caused by imp... |
| CVE-2024-13889 | HIGH | 7.2 | 0.7% | Mar 26, 2025 | The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ... |
| CVE-2024-13411 | MEDIUM | 6.4 | 0.3% | Mar 26, 2025 | The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in... |
| CVE-2024-13801 | HIGH | 8.1 | 0.3% | Mar 26, 2025 | The BWL Advanced FAQ Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a ... |
| CVE-2024-13702 | MEDIUM | 5.4 | 0.2% | Mar 26, 2025 | The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ... |
| CVE-2024-30155 | MEDIUM | 4.3 | 0.2% | Mar 26, 2025 | HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able t... |
| CVE-2024-13146 | HIGH | 8.8 | 0.2% | Mar 26, 2025 | The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow att... |
| CVE-2024-12683 | LOW | 3.5 | 0.2% | Mar 26, 2025 | The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-11847 | MEDIUM | 4.8 | 0.2% | Mar 26, 2025 | The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least ... |
| CVE-2024-47516 | CRITICAL | 9.8 | 0.8% | Mar 26, 2025 | A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to re... |
| CVE-2024-55030 | CRITICAL | 9.8 | 1.7% | Mar 25, 2025 | A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute ar... |
| CVE-2024-55029 | MEDIUM | 6.1 | 0.3% | Mar 25, 2025 | NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. |
| CVE-2024-55028 | CRITICAL | 9.8 | 0.7% | Mar 25, 2025 | A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now