2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56517 | MEDIUM | 5.3 | 0.6% | Dec 30, 2024 | LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 con... |
| CVE-2024-56516 | MEDIUM | 6.9 | 0.3% | Dec 30, 2024 | free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API f... |
| CVE-2024-52294 | MEDIUM | 4.3 | 0.4% | Dec 30, 2024 | Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR... |
| CVE-2024-12836 | HIGH | 7.8 | 0.3% | Dec 30, 2024 | Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2024-12835 | HIGH | 7.8 | 0.3% | Dec 30, 2024 | Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabilit... |
| CVE-2024-12834 | HIGH | 7.8 | 0.4% | Dec 30, 2024 | Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2024-12828 | HIGH | 8.8 | 32.0% | Dec 30, 2024 | Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ... |
| CVE-2024-12754 | MEDIUM | 5.5 | 1.2% | Dec 30, 2024 | AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensi... |
| CVE-2024-50703 | HIGH | 8.1 | 0.4% | Dec 30, 2024 | TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. |
| CVE-2024-50702 | MEDIUM | 5.3 | 0.3% | Dec 30, 2024 | TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an adminis... |
| CVE-2024-50701 | MEDIUM | 4.3 | 0.3% | Dec 30, 2024 | TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a... |
| CVE-2024-54181 | HIGH | 7.2 | 1.0% | Dec 30, 2024 | IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to exe... |
| CVE-2024-10044 | CRITICAL | 9.3 | 0.5% | Dec 30, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro... |
| CVE-2024-12993 | MEDIUM | 4.8 | 0.2% | Dec 30, 2024 | Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An atta... |
| CVE-2024-47926 | CRITICAL | 9.8 | 0.5% | Dec 30, 2024 | Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2024-47925 | HIGH | 7.5 | 0.5% | Dec 30, 2024 | Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-47924 | HIGH | 7.5 | 0.5% | Dec 30, 2024 | Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-47923 | MEDIUM | 5.3 | 0.4% | Dec 30, 2024 | Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2024-47922 | HIGH | 7.5 | 0.5% | Dec 30, 2024 | Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2024-47921 | HIGH | 8.4 | 0.2% | Dec 30, 2024 | Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm |
| CVE-2024-47920 | HIGH | 7.5 | 0.5% | Dec 30, 2024 | Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-47919 | CRITICAL | 9.8 | 1.5% | Dec 30, 2024 | Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
| CVE-2024-47918 | MEDIUM | 6.1 | 0.3% | Dec 30, 2024 | Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
| CVE-2024-47917 | HIGH | 7.5 | 0.5% | Dec 30, 2024 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-22063 | CRITICAL | 9 | 0.8% | Dec 30, 2024 | The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can expl... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now