2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54223 | MEDIUM | 6.1 | 0.3% | Dec 9, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in reputeinfosystems ARForms... |
| CVE-2024-54217 | MEDIUM | 5.4 | 0.4% | Dec 9, 2024 | Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <=... |
| CVE-2024-53819 | MEDIUM | 5.3 | 0.5% | Dec 9, 2024 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects C... |
| CVE-2024-53818 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultima... |
| CVE-2024-53798 | MEDIUM | 5.4 | 0.3% | Dec 9, 2024 | Missing Authorization vulnerability in BAKKBONE Australia FloristPress bakkbone-florist-companion.This issue affects Flo... |
| CVE-2024-53791 | MEDIUM | 6.5 | 0.3% | Dec 9, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ogun Labs Lenxel C... |
| CVE-2024-53785 | MEDIUM | 4.3 | 0.4% | Dec 9, 2024 | Missing Authorization vulnerability in Alexander Volkov Chatter.This issue affects Chatter: from n/a through 1.0.1. |
| CVE-2024-46901 | MEDIUM | 4.3 | 1.9% | Dec 9, 2024 | Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn... |
| CVE-2024-12307 | MEDIUM | 4.3 | 0.2% | Dec 9, 2024 | A function-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows te... |
| CVE-2024-12306 | MEDIUM | 4.3 | 0.2% | Dec 9, 2024 | Multiple access control vulnerabilities in Unifiedtransform version 2.0 and potentially earlier versions allow unauthori... |
| CVE-2024-12305 | MEDIUM | 4.3 | 0.2% | Dec 9, 2024 | An object-level access control vulnerability in Unifiedtransform version 2.0 and potentially earlier versions allows una... |
| CVE-2024-9651 | MEDIUM | 6.1 | 0.4% | Dec 9, 2024 | The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-12359 | MEDIUM | 5.4 | 0.4% | Dec 9, 2024 | A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability ... |
| CVE-2024-12357 | MEDIUM | 5.3 | 0.4% | Dec 9, 2024 | A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affec... |
| CVE-2024-53285 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functi... |
| CVE-2024-53284 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setti... |
| CVE-2024-53283 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forwar... |
| CVE-2024-53282 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC F... |
| CVE-2024-53281 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functi... |
| CVE-2024-53280 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center pol... |
| CVE-2024-53279 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station funct... |
| CVE-2024-55582 | MEDIUM | 5.7 | 0.1% | Dec 9, 2024 | Oxide before 6 has unencrypted Control Plane datastores. |
| CVE-2024-55578 | MEDIUM | 4.3 | 0.3% | Dec 9, 2024 | Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log f... |
| CVE-2024-55566 | MEDIUM | 6.6 | 0.2% | Dec 9, 2024 | ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded... |
| CVE-2024-55565 | MEDIUM | 4.3 | 0.7% | Dec 9, 2024 | nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now