2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11944 | HIGH | 8.8 | 1.6% | Dec 30, 2024 | iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability al... |
| CVE-2024-56801 | CRITICAL | 9.8 | 0.7% | Dec 30, 2024 | Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version ... |
| CVE-2024-56800 | HIGH | 7.4 | 0.3% | Dec 30, 2024 | Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions pr... |
| CVE-2024-56799 | CRITICAL | 10 | 0.5% | Dec 30, 2024 | Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistak... |
| CVE-2024-46542 | MEDIUM | 6.5 | 0.6% | Dec 30, 2024 | Veritas / Arctera Data Insight before 7.1.1 allows Application Administrators to conduct SQL injection attacks. |
| CVE-2024-56734 | MEDIUM | 6.1 | 0.4% | Dec 30, 2024 | Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verif... |
| CVE-2024-56733 | MEDIUM | 5.7 | 0.2% | Dec 30, 2024 | Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has bee... |
| CVE-2024-56517 | MEDIUM | 5.3 | 0.6% | Dec 30, 2024 | LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 con... |
| CVE-2024-56516 | MEDIUM | 6.9 | 0.3% | Dec 30, 2024 | free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API f... |
| CVE-2024-52294 | MEDIUM | 4.3 | 0.4% | Dec 30, 2024 | Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR... |
| CVE-2024-12836 | HIGH | 7.8 | 0.3% | Dec 30, 2024 | Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2024-12835 | HIGH | 7.8 | 0.3% | Dec 30, 2024 | Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabilit... |
| CVE-2024-12834 | HIGH | 7.8 | 0.4% | Dec 30, 2024 | Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2024-12828 | HIGH | 8.8 | 32.0% | Dec 30, 2024 | Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute ... |
| CVE-2024-12754 | MEDIUM | 5.5 | 1.2% | Dec 30, 2024 | AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensi... |
| CVE-2024-50703 | HIGH | 8.1 | 0.4% | Dec 30, 2024 | TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. |
| CVE-2024-50702 | MEDIUM | 5.3 | 0.3% | Dec 30, 2024 | TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an adminis... |
| CVE-2024-50701 | MEDIUM | 4.3 | 0.3% | Dec 30, 2024 | TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a... |
| CVE-2024-54181 | HIGH | 7.2 | 1.0% | Dec 30, 2024 | IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to exe... |
| CVE-2024-10044 | CRITICAL | 9.3 | 0.5% | Dec 30, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro... |
| CVE-2024-12993 | MEDIUM | 4.8 | 0.2% | Dec 30, 2024 | Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An atta... |
| CVE-2024-47926 | CRITICAL | 9.8 | 0.5% | Dec 30, 2024 | Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2024-47925 | HIGH | 7.5 | 0.5% | Dec 30, 2024 | Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-47924 | HIGH | 7.5 | 0.5% | Dec 30, 2024 | Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-47923 | MEDIUM | 5.3 | 0.4% | Dec 30, 2024 | Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now