2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11454 | HIGH | 7.8 | 0.2% | Dec 9, 2024 | A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and ... |
| CVE-2024-54926 | HIGH | 8.8 | 0.6% | Dec 9, 2024 | A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allow... |
| CVE-2024-53450 | HIGH | 7.5 | 0.5% | Dec 9, 2024 | RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents... |
| CVE-2024-45761 | HIGH | 8.1 | 0.3% | Dec 9, 2024 | Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. ... |
| CVE-2024-45760 | HIGH | 8.8 | 0.3% | Dec 9, 2024 | Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A ... |
| CVE-2024-40582 | HIGH | 7.5 | 0.4% | Dec 9, 2024 | Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information. |
| CVE-2024-49600 | HIGH | 7.8 | 0.2% | Dec 9, 2024 | Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged att... |
| CVE-2024-54929 | HIGH | 7.2 | 0.5% | Dec 9, 2024 | KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php. |
| CVE-2024-54226 | HIGH | 7.1 | 0.2% | Dec 9, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This ... |
| CVE-2024-54225 | HIGH | 7.5 | 0.8% | Dec 9, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-54220 | HIGH | 7.1 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Servic... |
| CVE-2024-54219 | HIGH | 7.1 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thehp AIO Contact ... |
| CVE-2024-53816 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | Missing Authorization vulnerability in Themeum Tutor LMS Elementor Addons tutor-lms-elementor-addons.This issue affects ... |
| CVE-2024-53790 | HIGH | 7.5 | 0.7% | Dec 9, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ogun Labs Lenxel Core fo... |
| CVE-2024-12360 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as critical. T... |
| CVE-2024-12358 | HIGH | 8.8 | 4.8% | Dec 9, 2024 | A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown par... |
| CVE-2024-55580 | HIGH | 7.5 | 0.3% | Dec 9, 2024 | An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network ac... |
| CVE-2024-55579 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network ... |
| CVE-2024-12355 | HIGH | 7.8 | 0.3% | Dec 9, 2024 | A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affecte... |
| CVE-2024-12354 | HIGH | 7.8 | 0.4% | Dec 9, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0. Affecte... |
| CVE-2024-12353 | HIGH | 7.8 | 0.3% | Dec 9, 2024 | A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0.... |
| CVE-2024-12351 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file s... |
| CVE-2024-12350 | HIGH | 8.8 | 3.6% | Dec 9, 2024 | A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update... |
| CVE-2024-12349 | HIGH | 8.8 | 0.4% | Dec 9, 2024 | A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an un... |
| CVE-2024-12343 | HIGH | 8.8 | 4.7% | Dec 8, 2024 | A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown funct... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now