2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50630 | HIGH | 7.5 | 22.7% | Mar 19, 2025 | Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4... |
| CVE-2024-50629 | MEDIUM | 5.3 | 27.0% | Mar 19, 2025 | Improper encoding or escaping of output vulnerability in the webapi component in Synology BeeStation OS (BSM) before 1.1... |
| CVE-2024-12922 | CRITICAL | 9.8 | 0.5% | Mar 19, 2025 | The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation ... |
| CVE-2024-12295 | HIGH | 8.8 | 0.3% | Mar 19, 2025 | The BoomBox Theme Extensions plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers... |
| CVE-2024-11131 | CRITICAL | 9.8 | 0.7% | Mar 19, 2025 | A vulnerability regarding out-of-bounds read is found in the video interface. This allows remote attackers to execute ar... |
| CVE-2024-10442 | CRITICAL | 10 | 1.3% | Mar 19, 2025 | Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0... |
| CVE-2024-10445 | MEDIUM | 5.3 | 0.4% | Mar 19, 2025 | Improper certificate validation vulnerability in the update functionality in Synology BeeStation OS (BSM) before 1.1-653... |
| CVE-2024-10444 | HIGH | 7.5 | 0.2% | Mar 19, 2025 | Improper certificate validation vulnerability in the LDAP utilities in Synology DiskStation Manager (DSM) before 7.1.1-4... |
| CVE-2024-10441 | CRITICAL | 9.8 | 1.1% | Mar 19, 2025 | Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation OS (BSM) before... |
| CVE-2024-57151 | MEDIUM | 6.8 | 0.4% | Mar 18, 2025 | SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via... |
| CVE-2024-12563 | HIGH | 8.8 | 0.6% | Mar 18, 2025 | The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214... |
| CVE-2024-56347 | CRITICAL | 9.6 | 0.9% | Mar 18, 2025 | IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary comma... |
| CVE-2024-56346 | CRITICAL | 10 | 1.1% | Mar 18, 2025 | IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improp... |
| CVE-2024-57170 | MEDIUM | 6.5 | 0.8% | Mar 18, 2025 | SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" paramete... |
| CVE-2024-57169 | CRITICAL | 9.8 | 0.9% | Mar 18, 2025 | A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability... |
| CVE-2024-49822 | MEDIUM | 4.1 | 0.3% | Mar 18, 2025 | IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authentica... |
| CVE-2024-44314 | MEDIUM | 6.5 | 0.3% | Mar 18, 2025 | TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthor... |
| CVE-2024-44313 | HIGH | 8.1 | 0.6% | Mar 18, 2025 | TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which ... |
| CVE-2024-8997 | CRITICAL | 9.8 | 0.4% | Mar 18, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Confi... |
| CVE-2024-21760 | HIGH | 8.4 | 0.7% | Mar 18, 2025 | An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4... |
| CVE-2024-41975 | MEDIUM | 5.3 | 0.4% | Mar 18, 2025 | An unauthenticated remote attacker can gain limited information of the PLC network but the user management of the PLCs p... |
| CVE-2024-23943 | CRITICAL | 9.1 | 0.6% | Mar 18, 2025 | An unauthenticated remote attacker can gain access to the cloud API due to a lack of authentication for a critical funct... |
| CVE-2024-23942 | HIGH | 7.1 | 0.1% | Mar 18, 2025 | A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an att... |
| CVE-2024-56506 | — | — | — | Mar 17, 2025 | Rejected reason: Not used |
| CVE-2024-56505 | — | — | — | Mar 17, 2025 | Rejected reason: Not used |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now