2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46481 | MEDIUM | 6.1 | 0.3% | Jan 13, 2025 | The login page of Venki Supravizio BPM up to 18.1.1 is vulnerable to open redirect leading to reflected XSS. |
| CVE-2024-46921 | MEDIUM | 6.5 | 0.3% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330,... |
| CVE-2024-44771 | MEDIUM | 6.1 | 0.2% | Jan 13, 2025 | BigId PrivacyPortal v179 is vulnerable to Cross Site Scripting (XSS) via the "Label" field in the Report template functi... |
| CVE-2024-46920 | MEDIUM | 6.5 | 0.3% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a le... |
| CVE-2024-6352 | MEDIUM | 4.3 | 0.2% | Jan 13, 2025 | A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert |
| CVE-2024-57488 | MEDIUM | 6.5 | 0.3% | Jan 13, 2025 | Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter ... |
| CVE-2024-57487 | MEDIUM | 6.5 | 2.4% | Jan 13, 2025 | In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types a... |
| CVE-2024-54999 | MEDIUM | 6.5 | 0.4% | Jan 13, 2025 | MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General ... |
| CVE-2024-48883 | MEDIUM | 4.3 | 0.2% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108... |
| CVE-2024-46919 | MEDIUM | 5.3 | 0.3% | Jan 13, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a le... |
| CVE-2024-12211 | MEDIUM | 5.4 | 0.3% | Jan 13, 2025 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. |
| CVE-2024-52937 | MEDIUM | 6.7 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou... |
| CVE-2024-52936 | MEDIUM | 4.4 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data out... |
| CVE-2024-52935 | MEDIUM | 4.1 | 0.2% | Jan 13, 2025 | Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data ou... |
| CVE-2024-12568 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Workfl... |
| CVE-2024-12567 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its form s... |
| CVE-2024-12566 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form setti... |
| CVE-2024-11636 | MEDIUM | 4.8 | 0.3% | Jan 13, 2025 | The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of its Text B... |
| CVE-2024-51456 | MEDIUM | 5.9 | 0.3% | Jan 12, 2025 | IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obta... |
| CVE-2024-49785 | MEDIUM | 5.4 | 0.2% | Jan 12, 2025 | IBM watsonx.ai 1.1 through 2.0.3 and IBM watsonx.ai on Cloud Pak for Data 4.8 through 5.0.3 is vulnerable to cross-site ... |
| CVE-2024-57881 | MEDIUM | 5.5 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't call pfn_to_page() on possibly... |
| CVE-2024-57880 | MEDIUM | 5.5 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Add space for a terminator in... |
| CVE-2024-57879 | MEDIUM | 5.5 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: iso: Always release hdev at the end of i... |
| CVE-2024-57878 | MEDIUM | 6.1 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET for NT_ARM_FPM... |
| CVE-2024-57877 | MEDIUM | 6.1 | 0.2% | Jan 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: fix partial SETREGSET for NT_ARM_POE... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now