2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53967 | MEDIUM | 5.4 | 0.3% | Mar 19, 2025 | Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-42176 | HIGH | 8 | 0.2% | Mar 19, 2025 | HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous ... |
| CVE-2024-55551 | HIGH | 8.3 | 0.6% | Mar 19, 2025 | An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into... |
| CVE-2024-45644 | MEDIUM | 4.7 | 0.3% | Mar 19, 2025 | IBM Security ReaQta 3.12 allows a privileged user to upload or transfer files of dangerous types that can be automatical... |
| CVE-2024-13933 | HIGH | 8.8 | 0.2% | Mar 19, 2025 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request F... |
| CVE-2024-13442 | CRITICAL | 9.8 | 0.4% | Mar 19, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2024-12920 | HIGH | 8.8 | 0.4% | Mar 19, 2025 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access ... |
| CVE-2024-13790 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion ... |
| CVE-2024-12137 | HIGH | 7.6 | 0.2% | Mar 19, 2025 | Authentication Bypass by Capture-replay vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Session Hijacking. T... |
| CVE-2024-12136 | HIGH | 7.8 | 0.1% | Mar 19, 2025 | Missing Critical Step in Authentication vulnerability in Elfatek Elektronics ANKA JPD-00028 allows Authentication Bypass... |
| CVE-2024-13412 | HIGH | 7.5 | 0.3% | Mar 19, 2025 | The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2024-13410 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | The CozyStay and TinySalt plugins for WordPress are vulnerable to PHP Object Injection in all versions up to, and includ... |
| CVE-2024-50631 | HIGH | 7.5 | 24.9% | Mar 19, 2025 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in the system syncing... |
| CVE-2024-50630 | HIGH | 7.5 | 22.7% | Mar 19, 2025 | Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4... |
| CVE-2024-50629 | MEDIUM | 5.3 | 27.0% | Mar 19, 2025 | Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1... |
| CVE-2024-12922 | CRITICAL | 9.8 | 0.5% | Mar 19, 2025 | The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation ... |
| CVE-2024-12295 | HIGH | 8.8 | 0.3% | Mar 19, 2025 | The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers... |
| CVE-2024-11131 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute ar... |
| CVE-2024-10442 | CRITICAL | 10 | 1.3% | Mar 19, 2025 | Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0... |
| CVE-2024-10445 | MEDIUM | 5.3 | 0.4% | Mar 19, 2025 | Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-653... |
| CVE-2024-10444 | HIGH | 7.5 | 0.2% | Mar 19, 2025 | Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-4... |
| CVE-2024-10441 | CRITICAL | 9.8 | 1.1% | Mar 19, 2025 | Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before... |
| CVE-2024-57151 | MEDIUM | 6.8 | 0.4% | Mar 18, 2025 | SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via... |
| CVE-2024-12563 | HIGH | 8.8 | 0.6% | Mar 18, 2025 | The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214... |
| CVE-2024-56347 | CRITICAL | 9.6 | 0.9% | Mar 18, 2025 | IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary comma... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now