2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45819 | MEDIUM | 5.5 | 0.3% | Dec 19, 2024 | PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local ... |
| CVE-2024-45818 | MEDIUM | 6.5 | 0.2% | Dec 19, 2024 | The hypervisor contains code to accelerate VGA memory accesses for HVM guests, when the (virtual) VGA is in "standard" m... |
| CVE-2024-37962 | MEDIUM | 6.5 | 0.2% | Dec 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion In... |
| CVE-2024-12331 | MEDIUM | 4.3 | 0.3% | Dec 19, 2024 | The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2024-11616 | MEDIUM | 5.6 | 0.3% | Dec 19, 2024 | Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fet... |
| CVE-2024-12560 | MEDIUM | 6.5 | 0.4% | Dec 19, 2024 | The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Inf... |
| CVE-2024-11768 | MEDIUM | 5.3 | 0.3% | Dec 19, 2024 | The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to im... |
| CVE-2024-12121 | MEDIUM | 5.4 | 0.3% | Dec 19, 2024 | The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions... |
| CVE-2024-10548 | MEDIUM | 6.5 | 0.4% | Dec 19, 2024 | The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i... |
| CVE-2024-55603 | MEDIUM | 6.5 | 0.5% | Dec 19, 2024 | Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still ... |
| CVE-2024-56115 | MEDIUM | 6.1 | 0.5% | Dec 18, 2024 | A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It ... |
| CVE-2024-55239 | MEDIUM | 5.4 | 0.3% | Dec 18, 2024 | A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar... |
| CVE-2024-37649 | MEDIUM | 4.6 | 0.3% | Dec 18, 2024 | Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proxi... |
| CVE-2024-55232 | MEDIUM | 5.4 | 0.4% | Dec 18, 2024 | An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows un... |
| CVE-2024-55231 | MEDIUM | 4.3 | 0.3% | Dec 18, 2024 | An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unau... |
| CVE-2024-56140 | MEDIUM | 6.5 | 0.2% | Dec 18, 2024 | Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware a... |
| CVE-2024-45338 | MEDIUM | 5.3 | 0.9% | Dec 18, 2024 | An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, r... |
| CVE-2024-52593 | MEDIUM | 5.3 | 0.4% | Dec 18, 2024 | Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService... |
| CVE-2024-52592 | MEDIUM | 5.3 | 0.3% | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.u... |
| CVE-2024-52590 | MEDIUM | 6.5 | 0.3% | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService... |
| CVE-2024-52579 | MEDIUM | 5.4 | 0.2% | Dec 18, 2024 | Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check t... |
| CVE-2024-51470 | MEDIUM | 6.5 | 0.5% | Dec 18, 2024 | IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE... |
| CVE-2024-49201 | MEDIUM | 4.3 | 0.3% | Dec 18, 2024 | Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensit... |
| CVE-2024-47039 | MEDIUM | 5.5 | 0.2% | Dec 18, 2024 | In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This... |
| CVE-2024-55089 | MEDIUM | 4.1 | 0.2% | Dec 18, 2024 | Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now