2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54135 | HIGH | 8.8 | 0.7% | Dec 6, 2024 | ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are v... |
| CVE-2024-12254 | HIGH | 8.7 | 1.9% | Dec 6, 2024 | Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signa... |
| CVE-2024-54141 | HIGH | 7.5 | 0.5% | Dec 6, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, p... |
| CVE-2024-11738 | HIGH | 7.5 | 0.7% | Dec 6, 2024 | A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmente... |
| CVE-2024-54216 | HIGH | 7.7 | 0.5% | Dec 6, 2024 | Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForm... |
| CVE-2024-54209 | HIGH | 7.1 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Awesome ... |
| CVE-2024-54208 | HIGH | 7.1 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joni Halabi Block ... |
| CVE-2024-54205 | HIGH | 7.1 | 0.2% | Dec 6, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget postman-widget allows Cross Site Request Forgery... |
| CVE-2024-53825 | HIGH | 7.2 | 0.3% | Dec 6, 2024 | Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2024-53824 | HIGH | 7.5 | 0.6% | Dec 6, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-53821 | HIGH | 7.1 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Genetech Pie Regis... |
| CVE-2024-53817 | HIGH | 7.6 | 0.4% | Dec 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in acowebs Product La... |
| CVE-2024-53815 | HIGH | 8.5 | 0.5% | Dec 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DOTonPAPER Pinpoin... |
| CVE-2024-53812 | HIGH | 7.1 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jacques Malgrange ... |
| CVE-2024-53808 | HIGH | 7.2 | 0.6% | Dec 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms ne... |
| CVE-2024-53804 | HIGH | 7.5 | 0.6% | Dec 6, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Emb... |
| CVE-2024-53803 | HIGH | 8.8 | 0.5% | Dec 6, 2024 | Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access... |
| CVE-2024-21571 | HIGH | 8.1 | 0.2% | Dec 6, 2024 | Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables... |
| CVE-2024-10516 | HIGH | 8.1 | 6.5% | Dec 6, 2024 | The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and inc... |
| CVE-2024-10776 | HIGH | 8.2 | 0.5% | Dec 6, 2024 | Lua apps can be deployed, removed, started, reloaded or stopped without authorization via AppManager. This allows an att... |
| CVE-2024-10774 | HIGH | 7.3 | 0.4% | Dec 6, 2024 | Unauthenticated CROWN APIs allow access to critical functions. This leads to the accessibility of large parts of the web... |
| CVE-2024-10772 | HIGH | 8.8 | 0.3% | Dec 6, 2024 | Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high imp... |
| CVE-2024-10771 | HIGH | 8.8 | 1.1% | Dec 6, 2024 | Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code... |
| CVE-2024-53907 | HIGH | 7.5 | 1.4% | Dec 6, 2024 | An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method an... |
| CVE-2024-53142 | HIGH | 7.8 | 0.2% | Dec 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: initramfs: avoid filename buffer overrun The initr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now