2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53141 | HIGH | 7.8 | 0.4% | Dec 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap... |
| CVE-2024-11728 | HIGH | 7.5 | 13.3% | Dec 6, 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'vis... |
| CVE-2024-11460 | HIGH | 7.5 | 0.5% | Dec 6, 2024 | The Verowa Connect plugin for WordPress is vulnerable to SQL Injection via the 'search_string' parameter in all versions... |
| CVE-2024-11289 | HIGH | 8.1 | 0.7% | Dec 6, 2024 | The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via se... |
| CVE-2024-11323 | HIGH | 8.8 | 0.4% | Dec 6, 2024 | The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privil... |
| CVE-2024-11178 | HIGH | 8.1 | 0.6% | Dec 6, 2024 | The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. ... |
| CVE-2024-11585 | HIGH | 7.5 | 0.6% | Dec 6, 2024 | The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing ... |
| CVE-2024-10578 | HIGH | 8.8 | 1.3% | Dec 6, 2024 | The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability ... |
| CVE-2024-52798 | HIGH | 7.7 | 0.8% | Dec 5, 2024 | path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular exp... |
| CVE-2024-38910 | HIGH | 7.5 | 0.5% | Dec 5, 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in th... |
| CVE-2024-37862 | HIGH | 7.3 | 0.3% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-hum... |
| CVE-2024-37860 | HIGH | 7.3 | 0.3% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allo... |
| CVE-2024-30964 | HIGH | 7.8 | 0.2% | Dec 5, 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navig... |
| CVE-2024-30963 | HIGH | 7.8 | 0.2% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation... |
| CVE-2024-30962 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation... |
| CVE-2024-30961 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navig... |
| CVE-2024-53523 | HIGH | 7.5 | 0.7% | Dec 5, 2024 | JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file functi... |
| CVE-2024-53589 | HIGH | 8.4 | 0.3% | Dec 5, 2024 | GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex forma... |
| CVE-2024-11148 | HIGH | 8.7 | 0.4% | Dec 5, 2024 | In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when ha... |
| CVE-2024-12235 | HIGH | 8.8 | 0.6% | Dec 5, 2024 | A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared a... |
| CVE-2024-12130 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threa... |
| CVE-2024-11158 | HIGH | 8.5 | 0.2% | Dec 5, 2024 | An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a... |
| CVE-2024-11156 | HIGH | 7.8 | 0.2% | Dec 5, 2024 | An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a th... |
| CVE-2024-11155 | HIGH | 8.5 | 0.2% | Dec 5, 2024 | A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat acto... |
| CVE-2024-53490 | HIGH | 7.5 | 0.7% | Dec 5, 2024 | Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now