2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57439 | MEDIUM | 4.9 | 0.6% | Jan 29, 2025 | An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Ser... |
| CVE-2024-57438 | MEDIUM | 5.4 | 0.3% | Jan 29, 2025 | Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves highe... |
| CVE-2024-57437 | MEDIUM | 6.5 | 0.5% | Jan 29, 2025 | RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list. |
| CVE-2024-41140 | MEDIUM | 6.5 | 0.9% | Jan 29, 2025 | Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in th... |
| CVE-2024-13561 | MEDIUM | 6.4 | 0.3% | Jan 29, 2025 | The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_ov... |
| CVE-2024-57514 | MEDIUM | 4.8 | 0.9% | Jan 28, 2025 | The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listi... |
| CVE-2024-29869 | MEDIUM | 5.5 | 0.3% | Jan 28, 2025 | Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the fil... |
| CVE-2024-40674 | MEDIUM | 5.3 | 0.2% | Jan 28, 2025 | In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a ... |
| CVE-2024-40673 | MEDIUM | 6.5 | 0.3% | Jan 28, 2025 | In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Cod... |
| CVE-2024-8401 | MEDIUM | 5.4 | 0.3% | Jan 28, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when a... |
| CVE-2024-7881 | MEDIUM | 5.1 | 0.2% | Jan 28, 2025 | An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged locati... |
| CVE-2024-6351 | MEDIUM | 4.3 | 0.2% | Jan 28, 2025 | A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert |
| CVE-2024-11954 | MEDIUM | 4.8 | 1.0% | Jan 28, 2025 | A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown func... |
| CVE-2024-23953 | MEDIUM | 6.5 | 1.1% | Jan 28, 2025 | Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid s... |
| CVE-2024-13527 | MEDIUM | 5.4 | 0.2% | Jan 28, 2025 | The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-13521 | MEDIUM | 5.4 | 0.1% | Jan 28, 2025 | The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2024-13509 | MEDIUM | 6.1 | 0.3% | Jan 28, 2025 | The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in al... |
| CVE-2024-12807 | MEDIUM | 4.8 | 0.3% | Jan 28, 2025 | The Social Share Buttons for WordPress plugin through 2.7 does not sanitise and escape some of its settings, which could... |
| CVE-2024-12723 | MEDIUM | 6.1 | 0.3% | Jan 28, 2025 | The Infility Global WordPress plugin through 2.9.8 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2024-53881 | MEDIUM | 5.5 | 0.1% | Jan 28, 2025 | NVIDIA vGPU software contains a vulnerability in the host driver, where it can allow a guest to cause an interrupt storm... |
| CVE-2024-53869 | MEDIUM | 5.5 | 0.2% | Jan 28, 2025 | NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A suc... |
| CVE-2024-0147 | MEDIUM | 5.5 | 0.2% | Jan 28, 2025 | NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been free... |
| CVE-2024-0140 | MEDIUM | 6.8 | 0.2% | Jan 28, 2025 | NVIDIA RAPIDS contains a vulnerability in cuDF and cuML, where a user could cause a deserialization of untrusted data is... |
| CVE-2024-0137 | MEDIUM | 6.5 | 0.3% | Jan 28, 2025 | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le... |
| CVE-2024-45341 | MEDIUM | 6.1 | 0.5% | Jan 28, 2025 | A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that appl... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now