2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31670 | MEDIUM | 6.3 | 0.3% | Dec 12, 2024 | rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf f... |
| CVE-2024-52901 | MEDIUM | 6.5 | 0.5% | Dec 12, 2024 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to impro... |
| CVE-2024-55633 | MEDIUM | 6.5 | 2.6% | Dec 12, 2024 | Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access c... |
| CVE-2024-50584 | MEDIUM | 4.4 | 0.3% | Dec 12, 2024 | An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_i... |
| CVE-2024-28145 | MEDIUM | 5.9 | 0.5% | Dec 12, 2024 | An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malici... |
| CVE-2024-28144 | MEDIUM | 5.5 | 0.2% | Dec 12, 2024 | An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaw... |
| CVE-2024-54122 | MEDIUM | 4.7 | 0.1% | Dec 12, 2024 | Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may... |
| CVE-2024-47947 | MEDIUM | 4.7 | 0.5% | Dec 12, 2024 | Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ... |
| CVE-2024-36498 | MEDIUM | 4.7 | 0.5% | Dec 12, 2024 | Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ... |
| CVE-2024-36494 | MEDIUM | 4.7 | 0.5% | Dec 12, 2024 | Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ... |
| CVE-2024-28142 | MEDIUM | 4.7 | 0.4% | Dec 12, 2024 | Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in ... |
| CVE-2024-12271 | MEDIUM | 4.4 | 0.4% | Dec 12, 2024 | The 360 Javascript Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ref’ parameter in a... |
| CVE-2024-9387 | MEDIUM | 6.4 | 0.4% | Dec 12, 2024 | An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 bef... |
| CVE-2024-9367 | MEDIUM | 4.3 | 0.5% | Dec 12, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and... |
| CVE-2024-8647 | MEDIUM | 5.4 | 0.4% | Dec 12, 2024 | An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior t... |
| CVE-2024-8179 | MEDIUM | 5.4 | 0.3% | Dec 12, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.4.6, 17.5 before 17.5.4, and 17.... |
| CVE-2024-54102 | MEDIUM | 5.9 | 0.1% | Dec 12, 2024 | Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability may affect service ... |
| CVE-2024-54101 | MEDIUM | 5.5 | 0.1% | Dec 12, 2024 | Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability w... |
| CVE-2024-54096 | MEDIUM | 5.5 | 0.1% | Dec 12, 2024 | Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may aff... |
| CVE-2024-12570 | MEDIUM | 6.7 | 0.4% | Dec 12, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior ... |
| CVE-2024-12292 | MEDIUM | 4 | 0.2% | Dec 12, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 pr... |
| CVE-2024-12401 | MEDIUM | 4.4 | 0.6% | Dec 12, 2024 | A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager... |
| CVE-2024-12333 | MEDIUM | 6.5 | 0.4% | Dec 12, 2024 | The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.... |
| CVE-2024-12160 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due ... |
| CVE-2024-11760 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now