2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48893 | MEDIUM | 5.4 | 0.4% | Jan 14, 2025 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, ... |
| CVE-2024-47566 | MEDIUM | 6 | 0.2% | Jan 14, 2025 | A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder vers... |
| CVE-2024-46669 | MEDIUM | 6.5 | 0.6% | Jan 14, 2025 | An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSAS... |
| CVE-2024-46666 | MEDIUM | 5.3 | 0.7% | Jan 14, 2025 | An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.... |
| CVE-2024-46664 | MEDIUM | 4.9 | 0.5% | Jan 14, 2025 | A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privi... |
| CVE-2024-45326 | MEDIUM | 4.3 | 0.2% | Jan 14, 2025 | An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all ... |
| CVE-2024-40587 | MEDIUM | 6.7 | 0.6% | Jan 14, 2025 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-36510 | MEDIUM | 5.3 | 0.7% | Jan 14, 2025 | An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all version... |
| CVE-2024-36506 | MEDIUM | 5.3 | 0.5% | Jan 14, 2025 | An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 thr... |
| CVE-2024-36504 | MEDIUM | 6.5 | 0.7% | Jan 14, 2025 | An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 ... |
| CVE-2024-35278 | MEDIUM | 4.3 | 0.4% | Jan 14, 2025 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions ... |
| CVE-2024-32115 | MEDIUM | 5.5 | 1.0% | Jan 14, 2025 | A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 ... |
| CVE-2024-21758 | MEDIUM | 6.7 | 0.2% | Jan 14, 2025 | A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a pri... |
| CVE-2024-11863 | MEDIUM | 5.3 | 0.4% | Jan 14, 2025 | Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may l... |
| CVE-2024-45385 | MEDIUM | 6.1 | 0.3% | Jan 14, 2025 | A vulnerability has been identified in Industrial Edge Management OS (IEM-OS) (All versions). Affected components are vu... |
| CVE-2024-12240 | MEDIUM | 5.4 | 0.3% | Jan 14, 2025 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the row label param... |
| CVE-2024-13156 | MEDIUM | 6.4 | 0.3% | Jan 14, 2025 | The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to DOM-Based Stored Cross-... |
| CVE-2024-11736 | MEDIUM | 4.9 | 0.8% | Jan 14, 2025 | A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system ... |
| CVE-2024-11734 | MEDIUM | 6.5 | 1.0% | Jan 14, 2025 | A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change... |
| CVE-2024-12006 | MEDIUM | 5.3 | 0.5% | Jan 14, 2025 | The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2024-13323 | MEDIUM | 5.4 | 0.4% | Jan 14, 2025 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' sho... |
| CVE-2024-12298 | MEDIUM | 5.5 | 0.2% | Jan 14, 2025 | We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attac... |
| CVE-2024-12083 | MEDIUM | 6.6 | 0.6% | Jan 14, 2025 | Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these ... |
| CVE-2024-11396 | MEDIUM | 5.3 | 1.9% | Jan 14, 2025 | The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to Information ... |
| CVE-2024-56138 | MEDIUM | 4 | 0.1% | Jan 13, 2025 | notion-go is a collection of libraries for supporting sign and verify OCI artifacts. Based on Notary Project specificati... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now