2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10663 | MEDIUM | 4.3 | 0.2% | Dec 4, 2024 | The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-45206 | MEDIUM | 6.5 | 0.2% | Dec 4, 2024 | A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests t... |
| CVE-2024-45204 | MEDIUM | 4.3 | 0.4% | Dec 4, 2024 | A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak N... |
| CVE-2024-42457 | MEDIUM | 6.5 | 0.4% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by le... |
| CVE-2024-42451 | MEDIUM | 6.5 | 0.3% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. Th... |
| CVE-2024-11985 | MEDIUM | 4.4 | 0.3% | Dec 4, 2024 | An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2... |
| CVE-2024-11479 | MEDIUM | 5.1 | 0.4% | Dec 4, 2024 | A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user... |
| CVE-2024-53672 | MEDIUM | 6.3 | 0.4% | Dec 3, 2024 | A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run ... |
| CVE-2024-51773 | MEDIUM | 5.4 | 0.3% | Dec 3, 2024 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe... |
| CVE-2024-52548 | MEDIUM | 6.7 | 0.2% | Dec 3, 2024 | An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, an... |
| CVE-2024-52546 | MEDIUM | 5.3 | 0.8% | Dec 3, 2024 | An unauthenticated attacker can perform a null pointer dereference in the DHIP Service (UDP port 37810). This vulnerabil... |
| CVE-2024-52545 | MEDIUM | 6.5 | 0.7% | Dec 3, 2024 | An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability... |
| CVE-2024-45676 | MEDIUM | 4.3 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insuf... |
| CVE-2024-41776 | MEDIUM | 6.5 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an att... |
| CVE-2024-53867 | MEDIUM | 4.3 | 0.4% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0... |
| CVE-2024-52815 | MEDIUM | 5.3 | 0.5% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received ... |
| CVE-2024-37303 | MEDIUM | 5.3 | 0.4% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote part... |
| CVE-2024-25035 | MEDIUM | 5.3 | 0.3% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of... |
| CVE-2024-53999 | MEDIUM | 5.4 | 0.5% | Dec 3, 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor... |
| CVE-2024-53257 | MEDIUM | 4.9 | 0.4% | Dec 3, 2024 | Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vt... |
| CVE-2024-11200 | MEDIUM | 6.1 | 0.3% | Dec 3, 2024 | The Goodlayers Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘font-family’ parameter... |
| CVE-2024-9978 | MEDIUM | 5.5 | 0.1% | Dec 3, 2024 | in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
| CVE-2024-12082 | MEDIUM | 5.5 | 0.1% | Dec 3, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
| CVE-2024-11326 | MEDIUM | 6.1 | 0.3% | Dec 3, 2024 | The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ... |
| CVE-2024-12062 | MEDIUM | 4.3 | 0.3% | Dec 3, 2024 | The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now