2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12237 | MEDIUM | 4.3 | 0.4% | Jan 3, 2025 | The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in... |
| CVE-2024-56332 | MEDIUM | 5.3 | 0.8% | Jan 3, 2025 | Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions ... |
| CVE-2024-56412 | MEDIUM | 5.4 | 0.4% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56411 | MEDIUM | 5.4 | 0.3% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56410 | MEDIUM | 5.4 | 0.3% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-36613 | MEDIUM | 6.2 | 0.3% | Jan 3, 2025 | FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potent... |
| CVE-2024-56514 | MEDIUM | 5.3 | 0.7% | Jan 3, 2025 | Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes ... |
| CVE-2024-56409 | MEDIUM | 5.4 | 0.3% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56366 | MEDIUM | 5.4 | 0.3% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56365 | MEDIUM | 5.4 | 0.3% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-56408 | MEDIUM | 5.4 | 0.4% | Jan 3, 2025 | PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.... |
| CVE-2024-5591 | MEDIUM | 4.3 | 0.3% | Jan 3, 2025 | IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detaile... |
| CVE-2024-41780 | MEDIUM | 4.6 | 0.2% | Jan 3, 2025 | IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to n... |
| CVE-2024-12132 | MEDIUM | 4.3 | 0.4% | Jan 3, 2025 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to... |
| CVE-2024-53839 | MEDIUM | 5.5 | 0.1% | Jan 3, 2025 | In GetCellInfoList() of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. Th... |
| CVE-2024-53836 | MEDIUM | 6.7 | 0.1% | Jan 3, 2025 | In wbrc_bt_dev_write of wb_regon_coordinator.c, there is a possible out of bounds write due to a buffer overflow. This c... |
| CVE-2024-8447 | MEDIUM | 5.9 | 0.6% | Jan 2, 2025 | A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution... |
| CVE-2024-48197 | MEDIUM | 4.7 | 0.4% | Jan 2, 2025 | Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the... |
| CVE-2024-11717 | MEDIUM | 6.3 | 0.6% | Jan 2, 2025 | Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When... |
| CVE-2024-11716 | MEDIUM | 5.3 | 11.7% | Jan 2, 2025 | While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in log... |
| CVE-2024-56414 | MEDIUM | 5.5 | 0.1% | Jan 2, 2025 | Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (W... |
| CVE-2024-56413 | MEDIUM | 6.1 | 0.2% | Jan 2, 2025 | Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows... |
| CVE-2024-55542 | MEDIUM | 4.4 | 0.2% | Jan 2, 2025 | Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are aff... |
| CVE-2024-55541 | MEDIUM | 6.1 | 0.3% | Jan 2, 2025 | Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products ... |
| CVE-2024-12907 | MEDIUM | 5.3 | 0.4% | Jan 2, 2025 | Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parame... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now