2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8447 | MEDIUM | 5.9 | 0.6% | Jan 2, 2025 | A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution... |
| CVE-2024-48197 | MEDIUM | 4.7 | 0.4% | Jan 2, 2025 | Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the... |
| CVE-2024-56199 | HIGH | 7.6 | 0.4% | Jan 2, 2025 | phpMyFAQ is an open source FAQ web application. Starting no later than version 3.2.10 and prior to version 4.0.2, an att... |
| CVE-2024-11717 | MEDIUM | 6.3 | 0.6% | Jan 2, 2025 | Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When... |
| CVE-2024-11716 | MEDIUM | 5.3 | 11.7% | Jan 2, 2025 | While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in log... |
| CVE-2024-9950 | HIGH | 7.8 | 0.3% | Jan 2, 2025 | A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify compliance... |
| CVE-2024-56414 | MEDIUM | 5.5 | 0.1% | Jan 2, 2025 | Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (W... |
| CVE-2024-56413 | MEDIUM | 6.1 | 0.2% | Jan 2, 2025 | Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows... |
| CVE-2024-55543 | HIGH | 7.8 | 0.2% | Jan 2, 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2024-55542 | MEDIUM | 4.4 | 0.2% | Jan 2, 2025 | Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are aff... |
| CVE-2024-55541 | MEDIUM | 6.1 | 0.3% | Jan 2, 2025 | Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products ... |
| CVE-2024-55540 | HIGH | 7.8 | 0.2% | Jan 2, 2025 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2024-12907 | MEDIUM | 5.3 | 0.4% | Jan 2, 2025 | Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parame... |
| CVE-2024-56137 | HIGH | 7.2 | 0.8% | Jan 2, 2025 | MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large ... |
| CVE-2024-55538 | MEDIUM | 4 | 0.2% | Jan 2, 2025 | Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image ... |
| CVE-2024-49385 | MEDIUM | 5.5 | 0.1% | Jan 2, 2025 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True I... |
| CVE-2024-38732 | MEDIUM | 4.3 | 0.2% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Blog allows Cross Site Request Forgery.This issue ... |
| CVE-2024-38731 | MEDIUM | 4.3 | 0.2% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Marsian i-amaze allows Cross Site Request Forgery.This issue affects ... |
| CVE-2024-37931 | MEDIUM | 4.3 | 0.2% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Creativthemes Point allows Cross Site Request Forgery.This issue affe... |
| CVE-2024-37925 | MEDIUM | 5.4 | 0.2% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This ... |
| CVE-2024-37452 | MEDIUM | 4.3 | 0.2% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop Schema Lite allows Cross Site Request Forgery.This issue ... |
| CVE-2024-37438 | MEDIUM | 5.4 | 0.2% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Cross Site Reque... |
| CVE-2024-37241 | MEDIUM | 4.3 | 0.2% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager - Resume Manager allows Cross Site Request ... |
| CVE-2024-37237 | MEDIUM | 4.3 | 0.2% | Jan 2, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in fs-code FS Poster fs-poster allows Cross Site Request Forgery.This is... |
| CVE-2024-13111 | HIGH | 8.1 | 0.8% | Jan 2, 2025 | A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination Syste... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now