2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53985 | MEDIUM | 6.1 | 0.6% | Dec 2, 2024 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera... |
| CVE-2024-53989 | MEDIUM | 6.1 | 0.5% | Dec 2, 2024 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera... |
| CVE-2024-49581 | MEDIUM | 6.5 | 0.4% | Dec 2, 2024 | Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could ... |
| CVE-2024-5890 | MEDIUM | 5.1 | 0.3% | Dec 2, 2024 | ServiceNow has addressed an HTML injection vulnerability that was identified in the Now Platform. This vulnerability cou... |
| CVE-2024-53617 | MEDIUM | 4.8 | 0.5% | Dec 2, 2024 | A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via upl... |
| CVE-2024-53566 | MEDIUM | 5.5 | 0.3% | Dec 2, 2024 | An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows... |
| CVE-2024-53364 | MEDIUM | 5.4 | 0.3% | Dec 2, 2024 | A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php.... |
| CVE-2024-53259 | MEDIUM | 6.5 | 0.6% | Dec 2, 2024 | quic-go is an implementation of the QUIC protocol in Go. An off-path attacker can inject an ICMP Packet Too Large packet... |
| CVE-2024-53984 | MEDIUM | 4.3 | 0.4% | Dec 2, 2024 | Nanopb is a small code-size Protocol Buffers implementation. When the compile time option PB_ENABLE_MALLOC is enabled, ... |
| CVE-2024-53459 | MEDIUM | 5.4 | 0.3% | Dec 2, 2024 | Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter. |
| CVE-2024-8785 | MEDIUM | 5.3 | 9.5% | Dec 2, 2024 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create ... |
| CVE-2024-38827 | MEDIUM | 4.8 | 0.4% | Dec 2, 2024 | The usage of String.toLowerCase() and String.toUpperCase() has some Locale dependent exceptions that could potentially r... |
| CVE-2024-53784 | MEDIUM | 4.3 | 0.3% | Dec 2, 2024 | Missing Authorization vulnerability in E-goi Smart Marketing SMS and Newsletters Forms smart-marketing-for-wp allows Exp... |
| CVE-2024-53775 | MEDIUM | 4.3 | 0.2% | Dec 2, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in benmoreassynt DancePress (TRWA) dancepress-trwa allows Cross Site Req... |
| CVE-2024-53761 | MEDIUM | 5.4 | 0.2% | Dec 2, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in P Roy WP Revisions Manager wp-revisions-manager allows Cross Site Req... |
| CVE-2024-53741 | MEDIUM | 6.5 | 0.2% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Garrett Grimm Simp... |
| CVE-2024-53721 | MEDIUM | 6.5 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stachethemes Advan... |
| CVE-2024-53709 | MEDIUM | 6.5 | 0.3% | Dec 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Uddin Generi... |
| CVE-2024-53708 | MEDIUM | 5.3 | 0.5% | Dec 2, 2024 | Missing Authorization vulnerability in kekotron AI Quiz ai-quiz allows Accessing Functionality Not Properly Constrained ... |
| CVE-2024-53707 | MEDIUM | 4.3 | 0.2% | Dec 2, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in ahmeti Ahmeti Wp Güzel Sözler ahmeti-wp-guzel-sozler allows Cross Sit... |
| CVE-2024-53124 | MEDIUM | 4.7 | 0.2% | Dec 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: fix data-races around sk->sk_forward_alloc Sy... |
| CVE-2024-53123 | MEDIUM | 5.5 | 0.2% | Dec 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: mptcp: error out earlier on disconnect Eric report... |
| CVE-2024-53122 | MEDIUM | 5.5 | 0.2% | Dec 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: mptcp: cope racing subflow creation in mptcp_rcv_sp... |
| CVE-2024-53121 | MEDIUM | 5.5 | 0.2% | Dec 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: fs, lock FTE when checking if active The... |
| CVE-2024-53120 | MEDIUM | 5.5 | 0.2% | Dec 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: CT: Fix null-ptr-deref in add rule err f... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now