2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56775 | HIGH | 7.8 | 0.2% | Jan 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix handling of plane refcount [W... |
| CVE-2024-56772 | HIGH | 7.8 | 0.2% | Jan 8, 2025 | In the Linux kernel, the following vulnerability has been resolved: kunit: string-stream: Fix a UAF bug in kunit_init_s... |
| CVE-2024-51442 | HIGH | 8.8 | 2.2% | Jan 8, 2025 | Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specia... |
| CVE-2024-55656 | HIGH | 8.8 | 15.0% | Jan 8, 2025 | RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloo... |
| CVE-2024-55517 | HIGH | 8.8 | 0.5% | Jan 8, 2025 | An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the... |
| CVE-2024-51737 | HIGH | 7 | 0.4% | Jan 8, 2025 | RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticate... |
| CVE-2024-51480 | HIGH | 7 | 0.2% | Jan 8, 2025 | RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYIND... |
| CVE-2024-11423 | HIGH | 7.5 | 0.8% | Jan 8, 2025 | The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Cou... |
| CVE-2024-12854 | HIGH | 8.8 | 0.8% | Jan 8, 2025 | The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio... |
| CVE-2024-12853 | HIGH | 8.8 | 0.8% | Jan 8, 2025 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio... |
| CVE-2024-9939 | HIGH | 7.5 | 1.0% | Jan 8, 2025 | The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2... |
| CVE-2024-45033 | HIGH | 8.1 | 0.9% | Jan 8, 2025 | Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Pro... |
| CVE-2024-13186 | HIGH | 7.5 | 0.3% | Jan 8, 2025 | The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. |
| CVE-2024-13185 | HIGH | 7.5 | 0.3% | Jan 8, 2025 | The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. |
| CVE-2024-11939 | HIGH | 7.5 | 0.4% | Jan 8, 2025 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ para... |
| CVE-2024-13173 | HIGH | 7.5 | 0.3% | Jan 8, 2025 | The health module has insufficient restrictions on loading URLs, which may lead to some information leakage. |
| CVE-2024-11270 | HIGH | 8.8 | 0.9% | Jan 8, 2025 | The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missi... |
| CVE-2024-56449 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2024-56448 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulner... |
| CVE-2024-54121 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause feat... |
| CVE-2024-11816 | HIGH | 8.8 | 0.7% | Jan 8, 2025 | The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.... |
| CVE-2024-56447 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vul... |
| CVE-2024-56446 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Vulnerability of variables not being initialized in the notification module Impact: Successful exploitation of this vuln... |
| CVE-2024-56444 | HIGH | 7.5 | 0.3% | Jan 8, 2025 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability... |
| CVE-2024-56443 | HIGH | 7.5 | 0.2% | Jan 8, 2025 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now