2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50713 | CRITICAL | 9.8 | 0.5% | Dec 27, 2024 | SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/interface.php. |
| CVE-2024-56732 | CRITICAL | 9.3 | 0.5% | Dec 27, 2024 | HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_c... |
| CVE-2024-54454 | MEDIUM | 5.3 | 0.4% | Dec 27, 2024 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0... |
| CVE-2024-54453 | HIGH | 7.5 | 0.6% | Dec 27, 2024 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0... |
| CVE-2024-54452 | MEDIUM | 4.9 | 0.8% | Dec 27, 2024 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal ... |
| CVE-2024-54451 | MEDIUM | 4.8 | 0.3% | Dec 27, 2024 | A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.... |
| CVE-2024-54450 | CRITICAL | 9.4 | 0.5% | Dec 27, 2024 | An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentica... |
| CVE-2024-39025 | HIGH | 7.5 | 0.4% | Dec 27, 2024 | Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data. |
| CVE-2024-12991 | MEDIUM | 5.3 | 0.3% | Dec 27, 2024 | A vulnerability was found in Beijing Longda Jushang Technology DBShop商城系统 3.3 Release 231225. It has been declared as pr... |
| CVE-2024-53476 | MEDIUM | 5.9 | 0.6% | Dec 27, 2024 | A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to b... |
| CVE-2024-50945 | HIGH | 7.5 | 0.6% | Dec 27, 2024 | An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, all... |
| CVE-2024-50944 | CRITICAL | 9.8 | 1.0% | Dec 27, 2024 | Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shoppin... |
| CVE-2024-12990 | MEDIUM | 5.3 | 0.3% | Dec 27, 2024 | A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown ... |
| CVE-2024-12989 | MEDIUM | 6.9 | 0.4% | Dec 27, 2024 | A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is s... |
| CVE-2024-12988 | HIGH | 7.5 | 0.8% | Dec 27, 2024 | A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulne... |
| CVE-2024-56509 | HIGH | 8.6 | 0.7% | Dec 27, 2024 | changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se... |
| CVE-2024-56508 | HIGH | 7.6 | 0.4% | Dec 27, 2024 | LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerabilit... |
| CVE-2024-56507 | MEDIUM | 5.4 | 0.3% | Dec 27, 2024 | LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a reflected cross-site scr... |
| CVE-2024-12987 | CRITICAL | 9.8 | 98.1% | Dec 27, 2024 | A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an ... |
| CVE-2024-12986 | CRITICAL | 9.8 | 32.8% | Dec 27, 2024 | A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. Th... |
| CVE-2024-12856 | HIGH | 7.2 | 82.2% | Dec 27, 2024 | The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. A... |
| CVE-2024-56675 | HIGH | 7.8 | 0.2% | Dec 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF via mismatching bpf_prog/attachment RC... |
| CVE-2024-56674 | MEDIUM | 5.5 | 0.2% | Dec 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: virtio_net: correct netdev_tx_reset_queue() invocat... |
| CVE-2024-56673 | MEDIUM | 5.5 | 0.2% | Dec 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: riscv: mm: Do not call pmd dtor on vmemmap page tab... |
| CVE-2024-56672 | HIGH | 7 | 0.3% | Dec 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Fix UAF in blkcg_unpin_online() blkcg_... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now