2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8510 | MEDIUM | 5.3 | 0.4% | Mar 17, 2025 | N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Custom... |
| CVE-2024-44866 | MEDIUM | 6.8 | 0.3% | Mar 17, 2025 | A buffer overflow in the GuitarPro1::read function of MuseScore Studio v4.3.2 allows attackers to to execute arbitrary c... |
| CVE-2024-49561 | HIGH | 7.8 | 0.2% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Ass... |
| CVE-2024-49559 | HIGH | 8.8 | 0.5% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password... |
| CVE-2024-48831 | HIGH | 8.4 | 0.2% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthent... |
| CVE-2024-48828 | MEDIUM | 5.5 | 0.2% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Mana... |
| CVE-2024-48017 | MEDIUM | 6.5 | 1.2% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization... |
| CVE-2024-48015 | MEDIUM | 6.7 | 0.6% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization... |
| CVE-2024-48830 | HIGH | 7.8 | 0.7% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization... |
| CVE-2024-48013 | HIGH | 8.8 | 0.6% | Mar 17, 2025 | Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecess... |
| CVE-2024-9055 | MEDIUM | 4.2 | 0.2% | Mar 17, 2025 | The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allo... |
| CVE-2024-54027 | MEDIUM | 4.4 | 0.1% | Mar 17, 2025 | A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and... |
| CVE-2024-12992 | CRITICAL | 9.8 | 1.3% | Mar 17, 2025 | Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This ... |
| CVE-2024-12971 | HIGH | 8.8 | 59.4% | Mar 17, 2025 | Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affec... |
| CVE-2024-13602 | MEDIUM | 4.8 | 0.2% | Mar 16, 2025 | The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-13126 | MEDIUM | 4.6 | 0.5% | Mar 16, 2025 | The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htac... |
| CVE-2024-58103 | MEDIUM | 5.8 | 0.4% | Mar 16, 2025 | Square Wire before 5.2.0 does not enforce a recursion limit on nested groups in ByteArrayProtoReader32.kt and ProtoReade... |
| CVE-2024-13497 | MEDIUM | 6.1 | 0.3% | Mar 15, 2025 | The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable t... |
| CVE-2024-13847 | — | — | — | Mar 15, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-12336 | MEDIUM | 6.5 | 0.3% | Mar 15, 2025 | The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access of ... |
| CVE-2024-54449 | HIGH | 8.8 | 0.6% | Mar 14, 2025 | The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticat... |
| CVE-2024-54448 | HIGH | 7.2 | 0.5% | Mar 14, 2025 | The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying ... |
| CVE-2024-54447 | HIGH | 7.1 | 0.3% | Mar 14, 2025 | Saved search functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a time... |
| CVE-2024-54446 | HIGH | 7.1 | 0.3% | Mar 14, 2025 | Document history functionality contains a blind SQL injection that can be exploited by authenticated attackers. Using a ... |
| CVE-2024-54445 | HIGH | 8.7 | 0.3% | Mar 14, 2025 | Login functionality contains a blind SQL injection that can be exploited by unauthenticated attackers. Using a time-base... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now