2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54236 | HIGH | 7.1 | 0.4% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni Woo... |
| CVE-2024-54235 | HIGH | 7.1 | 0.4% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shiptimize Shiptim... |
| CVE-2024-54233 | HIGH | 7.1 | 0.4% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in overclokk Advanced... |
| CVE-2024-54231 | HIGH | 7.1 | 0.4% | Dec 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni Woo... |
| CVE-2024-55889 | HIGH | 7.2 | 2.1% | Dec 13, 2024 | phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record compon... |
| CVE-2024-22461 | HIGH | 8.8 | 0.7% | Dec 13, 2024 | Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote att... |
| CVE-2024-52066 | HIGH | 7.8 | 0.3% | Dec 13, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routin... |
| CVE-2024-52065 | HIGH | 7.1 | 0.2% | Dec 13, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-... |
| CVE-2024-52064 | HIGH | 7.1 | 0.2% | Dec 13, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core L... |
| CVE-2024-52063 | HIGH | 8.6 | 0.3% | Dec 13, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core L... |
| CVE-2024-52062 | HIGH | 7.8 | 0.2% | Dec 13, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core L... |
| CVE-2024-52060 | HIGH | 7.8 | 0.3% | Dec 13, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routin... |
| CVE-2024-52059 | HIGH | 7.8 | 0.2% | Dec 13, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or ... |
| CVE-2024-52058 | HIGH | 7.8 | 0.6% | Dec 13, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext ... |
| CVE-2024-10783 | HIGH | 8.1 | 2.3% | Dec 13, 2024 | The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable... |
| CVE-2024-11839 | HIGH | 7.5 | 0.3% | Dec 13, 2024 | Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitra... |
| CVE-2024-11836 | HIGH | 7.5 | 0.3% | Dec 13, 2024 | Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue a... |
| CVE-2024-11835 | HIGH | 7.5 | 0.4% | Dec 13, 2024 | Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.... |
| CVE-2024-21544 | HIGH | 8.6 | 0.6% | Dec 13, 2024 | Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL ... |
| CVE-2024-21543 | HIGH | 7.1 | 0.5% | Dec 13, 2024 | Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fai... |
| CVE-2024-9508 | HIGH | 8.5 | 0.2% | Dec 13, 2024 | Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose informat... |
| CVE-2024-12212 | HIGH | 8.5 | 0.2% | Dec 13, 2024 | The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supp... |
| CVE-2024-55888 | HIGH | 7.1 | 0.3% | Dec 12, 2024 | Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the p... |
| CVE-2024-55885 | HIGH | 7.5 | 0.3% | Dec 12, 2024 | beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a has... |
| CVE-2024-55879 | HIGH | 8.8 | 1.0% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now