2024 CVE Vulnerabilities
39,217 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54092 | CRITICAL | 9.8 | 0.7% | Apr 8, 2025 | A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device K... |
| CVE-2024-41794 | CRITICAL | 9.8 | 0.5% | Apr 8, 2025 | A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcod... |
| CVE-2024-58127 | CRITICAL | 9.1 | 0.2% | Apr 7, 2025 | Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w... |
| CVE-2024-58126 | CRITICAL | 9.1 | 0.2% | Apr 7, 2025 | Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w... |
| CVE-2024-58125 | CRITICAL | 9.1 | 0.2% | Apr 7, 2025 | Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w... |
| CVE-2024-58124 | CRITICAL | 9.1 | 0.2% | Apr 7, 2025 | Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w... |
| CVE-2024-51800 | CRITICAL | 9.8 | 0.4% | Apr 4, 2025 | Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: f... |
| CVE-2024-13645 | CRITICAL | 9.8 | 0.6% | Apr 4, 2025 | The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including,... |
| CVE-2024-13744 | CRITICAL | 9.8 | 0.6% | Apr 4, 2025 | The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida... |
| CVE-2024-22611 | CRITICAL | 9.8 | 5.0% | Apr 3, 2025 | OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.cl... |
| CVE-2024-38392 | CRITICAL | 9.1 | 0.4% | Apr 2, 2025 | Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remo... |
| CVE-2024-45064 | CRITICAL | 9.8 | 0.9% | Apr 2, 2025 | A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZ... |
| CVE-2024-39780 | CRITICAL | 9.8 | 0.3% | Apr 2, 2025 | A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for g... |
| CVE-2024-13553 | CRITICAL | 9.8 | 0.5% | Apr 1, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account t... |
| CVE-2024-56325 | CRITICAL | 9.8 | 78.2% | Apr 1, 2025 | Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Norm... |
| CVE-2024-54809 | CRITICAL | 9.8 | 0.6% | Mar 31, 2025 | Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header fu... |
| CVE-2024-54808 | CRITICAL | 9.8 | 0.7% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionSe... |
| CVE-2024-54807 | CRITICAL | 9.8 | 2.2% | Mar 31, 2025 | In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exe... |
| CVE-2024-54806 | CRITICAL | 9.8 | 1.0% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execu... |
| CVE-2024-54805 | CRITICAL | 9.8 | 2.2% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque... |
| CVE-2024-54804 | CRITICAL | 9.8 | 1.6% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque... |
| CVE-2024-54803 | CRITICAL | 9.8 | 1.6% | Mar 31, 2025 | Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque... |
| CVE-2024-54802 | CRITICAL | 9.8 | 0.6% | Mar 31, 2025 | In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow... |
| CVE-2024-13804 | CRITICAL | 9.8 | 0.4% | Mar 30, 2025 | Unauthenticated RCE in HPE Insight Cluster Management Utility |
| CVE-2024-56975 | CRITICAL | 9.8 | 0.6% | Mar 28, 2025 | InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerabilit... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now