2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13069 | MEDIUM | 5.4 | 0.4% | Dec 31, 2024 | A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected... |
| CVE-2024-12105 | MEDIUM | 6.5 | 42.4% | Dec 31, 2024 | In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that c... |
| CVE-2024-56229 | MEDIUM | 4.3 | 0.2% | Dec 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in SearchIQ SearchIQ searchiq.This issue affects SearchIQ: from n/a thro... |
| CVE-2024-56222 | MEDIUM | 5.4 | 0.2% | Dec 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Requ... |
| CVE-2024-56218 | MEDIUM | 4.3 | 0.1% | Dec 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in sevenspark Contact Form 7 – Dynamic Text Extension contact-form-7-dyn... |
| CVE-2024-56216 | MEDIUM | 6.5 | 0.4% | Dec 31, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-13067 | MEDIUM | 5.3 | 0.8% | Dec 31, 2024 | A vulnerability was found in CodeAstro Online Food Ordering System 1.0 and classified as critical. This issue affects so... |
| CVE-2024-13058 | MEDIUM | 4.8 | 0.4% | Dec 30, 2024 | An issue exists in SoftIron HyperCloud where authenticated, but non-admin users can create data pools, which could pote... |
| CVE-2024-13042 | MEDIUM | 5.3 | 0.4% | Dec 30, 2024 | A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been clas... |
| CVE-2024-11946 | MEDIUM | 6.5 | 0.3% | Dec 30, 2024 | iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This... |
| CVE-2024-46542 | MEDIUM | 6.5 | 0.6% | Dec 30, 2024 | Veritas / Arctera Data Insight before 7.1.1 allows Application Administrators to conduct SQL injection attacks. |
| CVE-2024-56734 | MEDIUM | 6.1 | 0.4% | Dec 30, 2024 | Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verif... |
| CVE-2024-56733 | MEDIUM | 5.7 | 0.2% | Dec 30, 2024 | Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has bee... |
| CVE-2024-56517 | MEDIUM | 5.3 | 0.6% | Dec 30, 2024 | LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 con... |
| CVE-2024-56516 | MEDIUM | 6.9 | 0.3% | Dec 30, 2024 | free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API f... |
| CVE-2024-52294 | MEDIUM | 4.3 | 0.4% | Dec 30, 2024 | Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR... |
| CVE-2024-12754 | MEDIUM | 5.5 | 1.2% | Dec 30, 2024 | AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensi... |
| CVE-2024-50702 | MEDIUM | 5.3 | 0.3% | Dec 30, 2024 | TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an adminis... |
| CVE-2024-50701 | MEDIUM | 4.3 | 0.3% | Dec 30, 2024 | TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a... |
| CVE-2024-12993 | MEDIUM | 4.8 | 0.2% | Dec 30, 2024 | Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An atta... |
| CVE-2024-47923 | MEDIUM | 5.3 | 0.4% | Dec 30, 2024 | Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2024-47918 | MEDIUM | 6.1 | 0.3% | Dec 30, 2024 | Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
| CVE-2024-13033 | MEDIUM | 6.1 | 0.3% | Dec 30, 2024 | A vulnerability, which was classified as problematic, has been found in code-projects Chat System 1.0. Affected by this ... |
| CVE-2024-13032 | MEDIUM | 4.9 | 0.5% | Dec 30, 2024 | A vulnerability classified as problematic was found in Antabot White-Jotter up to 0.2.2. Affected by this vulnerability ... |
| CVE-2024-13031 | MEDIUM | 4.8 | 0.4% | Dec 30, 2024 | A vulnerability classified as problematic has been found in Antabot White-Jotter up to 0.2.2. Affected is an unknown fun... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now