2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30962 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation... |
| CVE-2024-30961 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navig... |
| CVE-2024-53523 | HIGH | 7.5 | 0.7% | Dec 5, 2024 | JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file functi... |
| CVE-2024-53589 | HIGH | 8.4 | 0.3% | Dec 5, 2024 | GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex forma... |
| CVE-2024-11148 | HIGH | 8.7 | 0.4% | Dec 5, 2024 | In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when ha... |
| CVE-2024-12235 | HIGH | 8.8 | 0.6% | Dec 5, 2024 | A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared a... |
| CVE-2024-12130 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threa... |
| CVE-2024-11158 | HIGH | 8.5 | 0.2% | Dec 5, 2024 | An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a... |
| CVE-2024-11156 | HIGH | 7.8 | 0.2% | Dec 5, 2024 | An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a th... |
| CVE-2024-11155 | HIGH | 8.5 | 0.2% | Dec 5, 2024 | A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat acto... |
| CVE-2024-53490 | HIGH | 7.5 | 0.7% | Dec 5, 2024 | Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java. |
| CVE-2024-53857 | HIGH | 7.5 | 0.4% | Dec 5, 2024 | rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vul... |
| CVE-2024-53856 | HIGH | 7.5 | 0.4% | Dec 5, 2024 | rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by provi... |
| CVE-2024-53472 | HIGH | 8.8 | 0.3% | Dec 5, 2024 | WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF). |
| CVE-2024-11941 | HIGH | 7.5 | 0.4% | Dec 5, 2024 | A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, fr... |
| CVE-2024-53703 | HIGH | 8.1 | 12.7% | Dec 5, 2024 | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by... |
| CVE-2024-52271 | HIGH | 8.2 | 0.2% | Dec 5, 2024 | User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Display... |
| CVE-2024-45318 | HIGH | 8.1 | 1.0% | Dec 5, 2024 | A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buf... |
| CVE-2024-40763 | HIGH | 7.5 | 0.9% | Dec 5, 2024 | Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote aut... |
| CVE-2024-6515 | HIGH | 8.1 | 0.4% | Dec 5, 2024 | Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher p... |
| CVE-2024-54126 | HIGH | 8.5 | 0.1% | Dec 5, 2024 | This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upg... |
| CVE-2024-51548 | HIGH | 8.8 | 0.6% | Dec 5, 2024 | Dangerous File Upload vulnerabilities allow upload of malicious scripts. Affected products: ABB ASPECT - Enterprise v... |
| CVE-2024-51546 | HIGH | 7.5 | 1.5% | Dec 5, 2024 | Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPEC... |
| CVE-2024-51544 | HIGH | 8.2 | 13.5% | Dec 5, 2024 | Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected produc... |
| CVE-2024-51543 | HIGH | 7.5 | 0.3% | Dec 5, 2024 | Information Disclosure vulnerabilities allow access to application configuration information. Affected products: ABB ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now