2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54852 | CRITICAL | 9.8 | 0.7% | Jan 29, 2025 | When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnera... |
| CVE-2024-54851 | HIGH | 8.8 | 0.3% | Jan 29, 2025 | Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection. |
| CVE-2024-51182 | MEDIUM | 6.1 | 0.3% | Jan 29, 2025 | HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML c... |
| CVE-2024-48761 | HIGH | 8.8 | 0.6% | Jan 29, 2025 | Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScr... |
| CVE-2024-23733 | HIGH | 7.5 | 2.3% | Jan 29, 2025 | The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core... |
| CVE-2024-12705 | HIGH | 7.5 | 16.2% | Jan 29, 2025 | Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or i... |
| CVE-2024-11187 | HIGH | 7.5 | 14.7% | Jan 29, 2025 | It is possible to construct a zone such that some queries to it will generate responses containing numerous records in t... |
| CVE-2024-48852 | CRITICAL | 9.4 | 2.4% | Jan 29, 2025 | Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly di... |
| CVE-2024-48849 | CRITICAL | 9.4 | 0.9% | Jan 29, 2025 | Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauth... |
| CVE-2024-10001 | HIGH | 7.1 | 0.4% | Jan 29, 2025 | A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious cod... |
| CVE-2024-57439 | MEDIUM | 4.9 | 0.6% | Jan 29, 2025 | An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Ser... |
| CVE-2024-57438 | MEDIUM | 5.4 | 0.3% | Jan 29, 2025 | Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves highe... |
| CVE-2024-57437 | MEDIUM | 6.5 | 0.5% | Jan 29, 2025 | RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list. |
| CVE-2024-57436 | HIGH | 7.2 | 0.6% | Jan 29, 2025 | RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring... |
| CVE-2024-54462 | HIGH | 7.1 | 0.2% | Jan 29, 2025 | The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious docu... |
| CVE-2024-54461 | HIGH | 7.1 | 0.2% | Jan 29, 2025 | The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious doc... |
| CVE-2024-41140 | MEDIUM | 6.5 | 0.9% | Jan 29, 2025 | Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in th... |
| CVE-2024-13561 | MEDIUM | 6.4 | 0.3% | Jan 29, 2025 | The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_ov... |
| CVE-2024-57965 | CRITICAL | 9.8 | 0.4% | Jan 29, 2025 | In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a po... |
| CVE-2024-7695 | HIGH | 8.7 | 0.7% | Jan 29, 2025 | Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient inp... |
| CVE-2024-13696 | HIGH | 7.2 | 0.4% | Jan 29, 2025 | The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored... |
| CVE-2024-12749 | HIGH | 7.1 | 0.6% | Jan 29, 2025 | The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2024-57519 | HIGH | 7.5 | 0.7% | Jan 28, 2025 | An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in ... |
| CVE-2024-56529 | HIGH | 7.1 | 0.4% | Jan 28, 2025 | Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a sess... |
| CVE-2024-48310 | HIGH | 7.5 | 0.5% | Jan 28, 2025 | AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now