2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52592 | MEDIUM | 5.3 | 0.3% | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.u... |
| CVE-2024-52590 | MEDIUM | 6.5 | 0.3% | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService... |
| CVE-2024-52579 | MEDIUM | 5.4 | 0.2% | Dec 18, 2024 | Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check t... |
| CVE-2024-51470 | MEDIUM | 6.5 | 0.5% | Dec 18, 2024 | IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE... |
| CVE-2024-49201 | MEDIUM | 4.3 | 0.3% | Dec 18, 2024 | Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensit... |
| CVE-2024-47039 | MEDIUM | 5.5 | 0.2% | Dec 18, 2024 | In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This... |
| CVE-2024-55089 | MEDIUM | 4.1 | 0.2% | Dec 18, 2024 | Rhymix before 2.1.24 is vulnerable to Server-Side Request Forgery (SSRF) in the background import data function because ... |
| CVE-2024-55492 | MEDIUM | 6.1 | 0.3% | Dec 18, 2024 | Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS). |
| CVE-2024-45082 | MEDIUM | 5.2 | 0.2% | Dec 18, 2024 | IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing... |
| CVE-2024-41752 | MEDIUM | 6.1 | 0.3% | Dec 18, 2024 | IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker ... |
| CVE-2024-25042 | MEDIUM | 6.1 | 0.3% | Dec 18, 2024 | IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripti... |
| CVE-2024-52361 | MEDIUM | 5.7 | 0.5% | Dec 18, 2024 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 stores user credentials in plain text which can be re... |
| CVE-2024-56128 | MEDIUM | 5.3 | 0.8% | Dec 18, 2024 | Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafk... |
| CVE-2024-50570 | MEDIUM | 5 | 0.1% | Dec 18, 2024 | A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 th... |
| CVE-2024-55997 | MEDIUM | 6.5 | 0.4% | Dec 18, 2024 | Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-locati... |
| CVE-2024-52485 | MEDIUM | 6.5 | 0.3% | Dec 18, 2024 | Missing Authorization vulnerability in Yudiz Solutions Ltd. WP Menu Image wp-menu-image allows Exploiting Incorrectly Co... |
| CVE-2024-11926 | MEDIUM | 6.5 | 0.3% | Dec 18, 2024 | The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-11291 | MEDIUM | 5.3 | 0.5% | Dec 18, 2024 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres... |
| CVE-2024-47104 | MEDIUM | 6.8 | 0.3% | Dec 18, 2024 | IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with auth... |
| CVE-2024-12554 | MEDIUM | 5.4 | 0.2% | Dec 18, 2024 | The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2024-12454 | MEDIUM | 6.1 | 0.2% | Dec 18, 2024 | The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2024-12340 | MEDIUM | 4.3 | 0.3% | Dec 18, 2024 | The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2024-11295 | MEDIUM | 5.3 | 0.5% | Dec 18, 2024 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2024-56175 | MEDIUM | 6.1 | 0.2% | Dec 18, 2024 | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ... |
| CVE-2024-56173 | MEDIUM | 4.7 | 0.3% | Dec 18, 2024 | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now