2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11736 | MEDIUM | 4.9 | 0.8% | Jan 14, 2025 | A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system ... |
| CVE-2024-11734 | MEDIUM | 6.5 | 0.9% | Jan 14, 2025 | A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change... |
| CVE-2024-12006 | MEDIUM | 5.3 | 0.5% | Jan 14, 2025 | The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2024-13323 | MEDIUM | 5.4 | 0.4% | Jan 14, 2025 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' sho... |
| CVE-2024-12298 | MEDIUM | 5.5 | 0.2% | Jan 14, 2025 | We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attac... |
| CVE-2024-12083 | MEDIUM | 6.6 | 0.6% | Jan 14, 2025 | Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these ... |
| CVE-2024-11396 | MEDIUM | 5.3 | 1.9% | Jan 14, 2025 | The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information ... |
| CVE-2024-56138 | MEDIUM | 4 | 0.1% | Jan 13, 2025 | notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specificati... |
| CVE-2024-46481 | MEDIUM | 6.1 | 0.3% | Jan 13, 2025 | The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS. |
| CVE-2024-46921 | MEDIUM | 6.5 | 0.3% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330,... |
| CVE-2024-44771 | MEDIUM | 6.1 | 0.2% | Jan 13, 2025 | BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template functi... |
| CVE-2024-46920 | MEDIUM | 6.5 | 0.3% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a le... |
| CVE-2024-6352 | MEDIUM | 4.3 | 0.2% | Jan 13, 2025 | A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert |
| CVE-2024-57488 | MEDIUM | 6.5 | 0.3% | Jan 13, 2025 | Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter ... |
| CVE-2024-57487 | MEDIUM | 6.5 | 2.4% | Jan 13, 2025 | In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types a... |
| CVE-2024-54999 | MEDIUM | 6.5 | 0.4% | Jan 13, 2025 | MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General ... |
| CVE-2024-48883 | MEDIUM | 4.3 | 0.2% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108... |
| CVE-2024-46919 | MEDIUM | 5.3 | 0.3% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a le... |
| CVE-2024-12211 | MEDIUM | 5.4 | 0.3% | Jan 13, 2025 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. |
| CVE-2024-52937 | MEDIUM | 6.7 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou... |
| CVE-2024-52936 | MEDIUM | 4.4 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data out... |
| CVE-2024-52935 | MEDIUM | 4.1 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou... |
| CVE-2024-12568 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workfl... |
| CVE-2024-12567 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form s... |
| CVE-2024-12566 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form setti... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now