2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53982 | HIGH | 8.7 | 0.5% | Dec 4, 2024 | ZOO-Project is a C-based WPS (Web Processing Service) implementation. A path traversal vulnerability was discovered in Z... |
| CVE-2024-50947 | HIGH | 7.5 | 0.4% | Dec 4, 2024 | An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2024-39219 | HIGH | 8.8 | 0.4% | Dec 4, 2024 | An issue in Aginode GigaSwitch V5 before version 7.06G allows authenticated attackers with Administrator privileges to u... |
| CVE-2024-12149 | HIGH | 8.1 | 0.6% | Dec 4, 2024 | Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0... |
| CVE-2024-12147 | HIGH | 7.1 | 0.8% | Dec 4, 2024 | A vulnerability was found in Netgear R6900 1.0.1.26_1.0.20. It has been declared as critical. Affected by this vulnerabi... |
| CVE-2024-39163 | HIGH | 8.8 | 0.2% | Dec 4, 2024 | binux pyspider up to v0.3.10 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Flask endpoints. |
| CVE-2024-54134 | HIGH | 8.3 | 0.4% | Dec 4, 2024 | A publish-access account was compromised for `@solana/web3.js`, a JavaScript library that is commonly used by Solana dap... |
| CVE-2024-37575 | HIGH | 7.5 | 0.4% | Dec 4, 2024 | The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no perm... |
| CVE-2024-37574 | HIGH | 8.2 | 0.3% | Dec 4, 2024 | The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to ... |
| CVE-2024-11643 | HIGH | 8.8 | 0.7% | Dec 4, 2024 | The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead... |
| CVE-2024-53139 | HIGH | 7.8 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix possible UAF in sctp_v6_available() A lo... |
| CVE-2024-53133 | HIGH | 7.8 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to a... |
| CVE-2024-53126 | HIGH | 7.8 | 0.2% | Dec 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: vdpa: solidrun: Fix UB bug with devres In psnet_op... |
| CVE-2024-51465 | HIGH | 8.8 | 0.7% | Dec 4, 2024 | IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authent... |
| CVE-2024-12138 | HIGH | 8.8 | 0.7% | Dec 4, 2024 | A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request... |
| CVE-2024-8894 | HIGH | 8.1 | 0.2% | Dec 4, 2024 | Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DW... |
| CVE-2024-52269 | HIGH | 8.2 | 0.3% | Dec 4, 2024 | User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The Saa... |
| CVE-2024-52277 | HIGH | 8.2 | 0.2% | Dec 4, 2024 | User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displaye... |
| CVE-2024-52276 | HIGH | 8.2 | 0.3% | Dec 4, 2024 | User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. 1. Disp... |
| CVE-2024-12107 | HIGH | 7.5 | 0.5% | Dec 4, 2024 | Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause... |
| CVE-2024-11952 | HIGH | 7.5 | 0.9% | Dec 4, 2024 | The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all... |
| CVE-2024-10567 | HIGH | 7.5 | 0.4% | Dec 4, 2024 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2024-11293 | HIGH | 8.1 | 0.5% | Dec 4, 2024 | The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & ... |
| CVE-2024-11398 | HIGH | 8.1 | 0.6% | Dec 4, 2024 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality ... |
| CVE-2024-9404 | HIGH | 8.7 | 0.7% | Dec 4, 2024 | This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now