2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53345 | HIGH | 8.8 | 1.3% | Jan 7, 2025 | An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to ex... |
| CVE-2024-52813 | MEDIUM | 4.3 | 0.5% | Jan 7, 2025 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust c... |
| CVE-2024-48245 | HIGH | 7.2 | 1.0% | Jan 7, 2025 | Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in var... |
| CVE-2024-46603 | HIGH | 7.5 | 0.7% | Jan 7, 2025 | An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows att... |
| CVE-2024-46602 | HIGH | 7.5 | 0.7% | Jan 7, 2025 | An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) v... |
| CVE-2024-46601 | HIGH | 7.5 | 0.6% | Jan 7, 2025 | Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow. |
| CVE-2024-46242 | HIGH | 7.5 | 0.7% | Jan 7, 2025 | An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a R... |
| CVE-2024-40702 | HIGH | 8.2 | 0.3% | Jan 7, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid t... |
| CVE-2024-28778 | MEDIUM | 6.5 | 0.5% | Jan 7, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys.... |
| CVE-2024-25037 | MEDIUM | 4.3 | 0.5% | Jan 7, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive ... |
| CVE-2024-11681 | MEDIUM | 6.9 | 0.5% | Jan 7, 2025 | A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running por... |
| CVE-2024-45640 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | IBM Security ReaQta 3.12 returns sensitive information in an HTTP response that could be used in further attacks against... |
| CVE-2024-45100 | MEDIUM | 4.9 | 0.5% | Jan 7, 2025 | IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration r... |
| CVE-2024-12738 | MEDIUM | 6.1 | 0.4% | Jan 7, 2025 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2024-12426 | MEDIUM | 6.5 | 0.5% | Jan 7, 2025 | Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document... |
| CVE-2024-12131 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to... |
| CVE-2024-52893 | MEDIUM | 5.3 | 0.4% | Jan 7, 2025 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive informa... |
| CVE-2024-52891 | MEDIUM | 5.4 | 0.3% | Jan 7, 2025 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow an authenticated user to inject malicious inf... |
| CVE-2024-52367 | HIGH | 7.5 | 0.3% | Jan 7, 2025 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could disclose sensitive system information to an unauthori... |
| CVE-2024-52366 | MEDIUM | 5.9 | 0.3% | Jan 7, 2025 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive informati... |
| CVE-2024-12711 | MEDIUM | 5.3 | 0.3% | Jan 7, 2025 | The RSVP and Event Management plugin for WordPress is vulnerable to unauthorized access due to a missing capability chec... |
| CVE-2024-12532 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | The BWD Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and... |
| CVE-2024-12425 | LOW | 3.3 | 0.3% | Jan 7, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation ... |
| CVE-2024-12316 | MEDIUM | 5.3 | 0.4% | Jan 7, 2025 | The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o... |
| CVE-2024-12033 | MEDIUM | 4.3 | 0.3% | Jan 7, 2025 | The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sy... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now