2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49336 | MEDIUM | 5.4 | 0.2% | Dec 19, 2024 | IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated... |
| CVE-2024-12793 | MEDIUM | 4.3 | 0.5% | Dec 19, 2024 | A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is ... |
| CVE-2024-52896 | MEDIUM | 6.2 | 0.3% | Dec 19, 2024 | IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive infor... |
| CVE-2024-12798 | MEDIUM | 5.9 | 0.4% | Dec 19, 2024 | ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core upto including version 0.1 to 1.3.14 and 1.4.0 t... |
| CVE-2024-47093 | MEDIUM | 6.1 | 0.5% | Dec 19, 2024 | Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS |
| CVE-2024-9102 | MEDIUM | 5 | 0.4% | Dec 19, 2024 | phpLDAPadmin since at least version 1.2.0 through the latest version 1.2.6.7 allows users to export elements from the LD... |
| CVE-2024-12783 | MEDIUM | 6.1 | 0.4% | Dec 19, 2024 | A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affect... |
| CVE-2024-45819 | MEDIUM | 5.5 | 0.3% | Dec 19, 2024 | PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local ... |
| CVE-2024-45818 | MEDIUM | 6.5 | 0.2% | Dec 19, 2024 | The hypervisor contains code to accelerate VGA memory accesses for HVM guests, when the (virtual) VGA is in "standard" m... |
| CVE-2024-37962 | MEDIUM | 6.5 | 0.2% | Dec 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion In... |
| CVE-2024-12331 | MEDIUM | 4.3 | 0.3% | Dec 19, 2024 | The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2024-11616 | MEDIUM | 5.6 | 0.3% | Dec 19, 2024 | Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fet... |
| CVE-2024-12560 | MEDIUM | 6.5 | 0.4% | Dec 19, 2024 | The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Inf... |
| CVE-2024-11768 | MEDIUM | 5.3 | 0.3% | Dec 19, 2024 | The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to im... |
| CVE-2024-12121 | MEDIUM | 5.4 | 0.3% | Dec 19, 2024 | The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions... |
| CVE-2024-10548 | MEDIUM | 6.5 | 0.4% | Dec 19, 2024 | The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i... |
| CVE-2024-55603 | MEDIUM | 6.5 | 0.5% | Dec 19, 2024 | Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still ... |
| CVE-2024-56115 | MEDIUM | 6.1 | 0.5% | Dec 18, 2024 | A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It ... |
| CVE-2024-55239 | MEDIUM | 5.4 | 0.3% | Dec 18, 2024 | A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar... |
| CVE-2024-37649 | MEDIUM | 4.6 | 0.3% | Dec 18, 2024 | Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proxi... |
| CVE-2024-55232 | MEDIUM | 5.4 | 0.4% | Dec 18, 2024 | An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows un... |
| CVE-2024-55231 | MEDIUM | 4.3 | 0.3% | Dec 18, 2024 | An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unau... |
| CVE-2024-56140 | MEDIUM | 6.5 | 0.2% | Dec 18, 2024 | Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware a... |
| CVE-2024-45338 | MEDIUM | 5.3 | 0.9% | Dec 18, 2024 | An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, r... |
| CVE-2024-52593 | MEDIUM | 5.3 | 0.4% | Dec 18, 2024 | Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now