2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49818 | MEDIUM | 4.3 | 0.5% | Dec 17, 2024 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensi... |
| CVE-2024-49817 | MEDIUM | 4.4 | 0.2% | Dec 17, 2024 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files ... |
| CVE-2024-49816 | MEDIUM | 4.4 | 0.3% | Dec 17, 2024 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log... |
| CVE-2024-53144 | MEDIUM | 5.5 | 0.3% | Dec 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS parin... |
| CVE-2024-37607 | MEDIUM | 6.5 | 0.5% | Dec 17, 2024 | A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Servi... |
| CVE-2024-37606 | MEDIUM | 6.5 | 0.5% | Dec 17, 2024 | A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (D... |
| CVE-2024-37605 | MEDIUM | 6.5 | 0.6% | Dec 17, 2024 | A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service ... |
| CVE-2024-36831 | MEDIUM | 5.3 | 0.7% | Dec 17, 2024 | A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02... |
| CVE-2024-9819 | MEDIUM | 6.5 | 0.4% | Dec 17, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse.... |
| CVE-2024-54677 | MEDIUM | 5.3 | 1.9% | Dec 17, 2024 | Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to den... |
| CVE-2024-10356 | MEDIUM | 4.3 | 0.4% | Dec 17, 2024 | The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi... |
| CVE-2024-8475 | MEDIUM | 6.5 | 0.4% | Dec 17, 2024 | Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulati... |
| CVE-2024-8429 | MEDIUM | 4.3 | 0.4% | Dec 17, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows ... |
| CVE-2024-52542 | MEDIUM | 5.5 | 0.2% | Dec 17, 2024 | Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with... |
| CVE-2024-12601 | MEDIUM | 5.3 | 0.5% | Dec 17, 2024 | The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including,... |
| CVE-2024-12395 | MEDIUM | 6.1 | 0.5% | Dec 17, 2024 | The WooCommerce Additional Fees On Checkout (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-11280 | MEDIUM | 5.3 | 0.4% | Dec 17, 2024 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u... |
| CVE-2024-12469 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2024-12127 | MEDIUM | 6.1 | 0.3% | Dec 17, 2024 | The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vu... |
| CVE-2024-12024 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-11294 | MEDIUM | 5.3 | 0.5% | Dec 17, 2024 | The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-12220 | MEDIUM | 6.1 | 0.2% | Dec 17, 2024 | The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2024-12219 | MEDIUM | 6.1 | 0.2% | Dec 17, 2024 | The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2024-55864 | MEDIUM | 4.8 | 0.3% | Dec 17, 2024 | Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious... |
| CVE-2024-12239 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navig... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now