2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54359 | HIGH | 8.2 | 0.6% | Dec 16, 2024 | Missing Authorization vulnerability in Saul Morales Pacheco Banner System banner-system allows Exploiting Incorrectly Co... |
| CVE-2024-54358 | HIGH | 7.1 | 0.4% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enrico Cantori 3D ... |
| CVE-2024-54355 | HIGH | 8.8 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.T... |
| CVE-2024-54353 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in wpgear Hack-Info hack-info allows Stored XSS.This issue affects Hack-... |
| CVE-2024-54352 | HIGH | 8.8 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Sabri Sogrid sogrid allows Privilege Escalation.This issue affects So... |
| CVE-2024-54332 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allow... |
| CVE-2024-54331 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Micha I Plant A Tree i-plant-a-tree allows Stored XSS.This issue affe... |
| CVE-2024-12668 | HIGH | 8.2 | 0.2% | Dec 16, 2024 | Velocidex WinPmem versions below 4.1 suffer from an Out of Bounds Write vulnerability. By using an IO Control, a user sp... |
| CVE-2024-10972 | HIGH | 7.3 | 0.2% | Dec 16, 2024 | Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with... |
| CVE-2024-12478 | HIGH | 8.8 | 0.5% | Dec 16, 2024 | A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the ... |
| CVE-2024-12646 | HIGH | 8.1 | 0.3% | Dec 16, 2024 | The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local... |
| CVE-2024-12644 | HIGH | 7.1 | 0.3% | Dec 16, 2024 | The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web ser... |
| CVE-2024-12643 | HIGH | 8.1 | 0.3% | Dec 16, 2024 | The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local ... |
| CVE-2024-12642 | HIGH | 8.1 | 0.3% | Dec 16, 2024 | TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple loca... |
| CVE-2024-56086 | HIGH | 7.1 | 0.4% | Dec 16, 2024 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are... |
| CVE-2024-56084 | HIGH | 7.1 | 0.3% | Dec 16, 2024 | An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while crea... |
| CVE-2024-53376 | HIGH | 8.8 | 10.8% | Dec 16, 2024 | CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ... |
| CVE-2024-56083 | HIGH | 8.1 | 0.5% | Dec 16, 2024 | Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly... |
| CVE-2024-11858 | HIGH | 7.8 | 0.8% | Dec 15, 2024 | A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation wh... |
| CVE-2024-7701 | HIGH | 7.5 | 0.2% | Dec 15, 2024 | Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption B... |
| CVE-2024-56073 | HIGH | 7.5 | 0.6% | Dec 15, 2024 | An issue was discovered in FastNetMon Community Edition through 1.2.7. Zero-length templates for Netflow v9 allow remote... |
| CVE-2024-56072 | HIGH | 7.5 | 0.7% | Dec 15, 2024 | An issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to ca... |
| CVE-2024-55970 | HIGH | 7.5 | 0.5% | Dec 15, 2024 | File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the ... |
| CVE-2024-31892 | HIGH | 7.5 | 0.3% | Dec 14, 2024 | IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized act... |
| CVE-2024-31891 | HIGH | 7.8 | 0.2% | Dec 14, 2024 | IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulner... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now