2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10952 | HIGH | 7.3 | 0.6% | Dec 4, 2024 | The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJ... |
| CVE-2024-10587 | HIGH | 8.8 | 0.6% | Dec 4, 2024 | The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress... |
| CVE-2024-45207 | HIGH | 7 | 0.2% | Dec 4, 2024 | DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the a... |
| CVE-2024-45205 | HIGH | 7.1 | 0.1% | Dec 4, 2024 | An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Networ... |
| CVE-2024-42456 | HIGH | 8.8 | 0.4% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a me... |
| CVE-2024-42455 | HIGH | 8.1 | 14.0% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit i... |
| CVE-2024-42453 | HIGH | 8.1 | 0.3% | Dec 4, 2024 | A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected... |
| CVE-2024-42452 | HIGH | 8.8 | 0.5% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and... |
| CVE-2024-42449 | HIGH | 7.1 | 5.4% | Dec 4, 2024 | From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos... |
| CVE-2024-40717 | HIGH | 8.8 | 0.7% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code exe... |
| CVE-2024-46624 | HIGH | 8.8 | 0.4% | Dec 3, 2024 | An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via ... |
| CVE-2024-46625 | HIGH | 8.8 | 0.5% | Dec 3, 2024 | An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.... |
| CVE-2024-54131 | HIGH | 7.3 | 0.2% | Dec 3, 2024 | The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug ... |
| CVE-2024-51772 | HIGH | 8 | 0.4% | Dec 3, 2024 | An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenti... |
| CVE-2024-45757 | HIGH | 7.2 | 0.4% | Dec 3, 2024 | An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-set... |
| CVE-2024-51771 | HIGH | 8.8 | 0.7% | Dec 3, 2024 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe... |
| CVE-2024-51114 | HIGH | 8.8 | 0.8% | Dec 3, 2024 | An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute ar... |
| CVE-2024-50948 | HIGH | 7.5 | 0.6% | Dec 3, 2024 | mochiMQTT v2.6.3 is vulnerable to Denial of Service (DoS) due to improper resource management. An attacker can exhaust s... |
| CVE-2024-48080 | HIGH | 7.5 | 0.7% | Dec 3, 2024 | An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier i... |
| CVE-2024-12053 | HIGH | 8.8 | 0.8% | Dec 3, 2024 | Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object co... |
| CVE-2024-52547 | HIGH | 7.2 | 0.7% | Dec 3, 2024 | An authenticated attacker can trigger a stack based buffer overflow in the DHIP Service (TCP port 80). This vulnerabilit... |
| CVE-2024-41777 | HIGH | 7.5 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic k... |
| CVE-2024-41775 | HIGH | 7.5 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker ... |
| CVE-2024-52805 | HIGH | 7.5 | 0.7% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain conf... |
| CVE-2024-37302 | HIGH | 7.5 | 0.6% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now