2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53672 | MEDIUM | 6.3 | 0.4% | Dec 3, 2024 | A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run ... |
| CVE-2024-51773 | MEDIUM | 5.4 | 0.3% | Dec 3, 2024 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe... |
| CVE-2024-52548 | MEDIUM | 6.7 | 0.2% | Dec 3, 2024 | An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, an... |
| CVE-2024-52546 | MEDIUM | 5.3 | 0.8% | Dec 3, 2024 | An unauthenticated attacker can perform a null pointer dereference in the DHIP Service (UDP port 37810). This vulnerabil... |
| CVE-2024-52545 | MEDIUM | 6.5 | 0.7% | Dec 3, 2024 | An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability... |
| CVE-2024-45676 | MEDIUM | 4.3 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insuf... |
| CVE-2024-41776 | MEDIUM | 6.5 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an att... |
| CVE-2024-53867 | MEDIUM | 4.3 | 0.4% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0... |
| CVE-2024-52815 | MEDIUM | 5.3 | 0.5% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received ... |
| CVE-2024-37303 | MEDIUM | 5.3 | 0.4% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote part... |
| CVE-2024-25035 | MEDIUM | 5.3 | 0.3% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of... |
| CVE-2024-53999 | MEDIUM | 5.4 | 0.5% | Dec 3, 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor... |
| CVE-2024-53257 | MEDIUM | 4.9 | 0.4% | Dec 3, 2024 | Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vt... |
| CVE-2024-11200 | MEDIUM | 6.1 | 0.3% | Dec 3, 2024 | The Goodlayers Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘font-family’ parameter... |
| CVE-2024-9978 | MEDIUM | 5.5 | 0.1% | Dec 3, 2024 | in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
| CVE-2024-12082 | MEDIUM | 5.5 | 0.1% | Dec 3, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
| CVE-2024-11326 | MEDIUM | 6.1 | 0.3% | Dec 3, 2024 | The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ... |
| CVE-2024-12062 | MEDIUM | 4.3 | 0.3% | Dec 3, 2024 | The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in... |
| CVE-2024-11782 | MEDIUM | 5.4 | 0.3% | Dec 3, 2024 | The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' short... |
| CVE-2024-11325 | MEDIUM | 5.2 | 0.9% | Dec 3, 2024 | The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add... |
| CVE-2024-11866 | MEDIUM | 6.4 | 0.2% | Dec 3, 2024 | The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map'... |
| CVE-2024-11844 | MEDIUM | 4.3 | 0.3% | Dec 3, 2024 | The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2024-11898 | MEDIUM | 5.4 | 0.3% | Dec 3, 2024 | The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin... |
| CVE-2024-11853 | MEDIUM | 6.4 | 0.3% | Dec 3, 2024 | The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versio... |
| CVE-2024-11805 | MEDIUM | 6.1 | 0.3% | Dec 3, 2024 | The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now