2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9188 | HIGH | 8.8 | 0.5% | Jan 10, 2025 | Specially constructed queries cause cross platform scripting leaking administrator tokens |
| CVE-2024-9134 | HIGH | 8.3 | 0.6% | Jan 10, 2025 | Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application acce... |
| CVE-2024-9131 | HIGH | 7.2 | 1.4% | Jan 10, 2025 | A user with administrator privileges can perform command injection |
| CVE-2024-47520 | HIGH | 7.6 | 0.4% | Jan 10, 2025 | A user with advanced report application access rights can perform actions for which they are not authorized |
| CVE-2024-47519 | HIGH | 7.1 | 0.3% | Jan 10, 2025 | Backup uploads to ETM subject to man-in-the-middle interception |
| CVE-2024-47518 | HIGH | 7.6 | 0.4% | Jan 10, 2025 | Specially constructed queries targeting ETM could discover active remote access sessions |
| CVE-2024-54996 | HIGH | 8.8 | 0.8% | Jan 10, 2025 | MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and... |
| CVE-2024-6662 | HIGH | 8.7 | 0.3% | Jan 10, 2025 | Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form avail... |
| CVE-2024-57228 | HIGH | 8 | 1.2% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_... |
| CVE-2024-57227 | HIGH | 8 | 1.2% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc... |
| CVE-2024-57226 | HIGH | 8 | 1.2% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_... |
| CVE-2024-57211 | HIGH | 8 | 1.2% | Jan 10, 2025 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne para... |
| CVE-2024-54848 | HIGH | 7.4 | 0.3% | Jan 10, 2025 | Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communica... |
| CVE-2024-46210 | HIGH | 7.2 | 0.6% | Jan 10, 2025 | An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitra... |
| CVE-2024-25371 | HIGH | 7.5 | 0.4% | Jan 10, 2025 | Gramine before a390e33e16ed374a40de2344562a937f289be2e1 suffers from an Interface vulnerability due to mismatching SW si... |
| CVE-2024-41787 | HIGH | 8.1 | 1.1% | Jan 10, 2025 | IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security rest... |
| CVE-2024-51229 | HIGH | 8.8 | 0.8% | Jan 9, 2025 | Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via th... |
| CVE-2024-46464 | HIGH | 7.8 | 0.2% | Jan 9, 2025 | In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated... |
| CVE-2024-13311 | HIGH | 7.3 | 0.3% | Jan 9, 2025 | Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file ... |
| CVE-2024-13291 | HIGH | 7.3 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Ba... |
| CVE-2024-56113 | HIGH | 7.5 | 0.5% | Jan 9, 2025 | Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information ... |
| CVE-2024-54887 | HIGH | 8 | 6.1% | Jan 9, 2025 | TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2... |
| CVE-2024-13284 | HIGH | 8.8 | 0.2% | Jan 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects... |
| CVE-2024-13282 | HIGH | 8.8 | 0.3% | Jan 9, 2025 | Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block perm... |
| CVE-2024-13276 | HIGH | 7.5 | 0.4% | Jan 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now