2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43705 | HIGH | 7.8 | 0.1% | Dec 28, 2024 | Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to arbitrary read-only sy... |
| CVE-2024-54775 | MEDIUM | 4.8 | 0.3% | Dec 27, 2024 | Dcat-Admin v2.2.0-beta and v2.2.2-beta contains a Cross-Site Scripting (XSS) vulnerability via /admin/auth/menu and /adm... |
| CVE-2024-54774 | MEDIUM | 4.8 | 0.3% | Dec 27, 2024 | Dcat Admin v2.2.0-beta contains a cross-site scripting (XSS) vulnerability in /admin/articles/create. |
| CVE-2024-50714 | HIGH | 7.5 | 0.6% | Dec 27, 2024 | A Server-Side Request Forgery (SSRF) in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive ... |
| CVE-2024-50717 | CRITICAL | 9.8 | 0.8% | Dec 27, 2024 | SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the client par... |
| CVE-2024-50716 | CRITICAL | 9.8 | 0.8% | Dec 27, 2024 | SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary code via the id paramet... |
| CVE-2024-50715 | HIGH | 7.5 | 1.3% | Dec 27, 2024 | An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command inje... |
| CVE-2024-50713 | CRITICAL | 9.8 | 0.5% | Dec 27, 2024 | SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/interface.php. |
| CVE-2024-56732 | CRITICAL | 9.3 | 0.5% | Dec 27, 2024 | HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_c... |
| CVE-2024-54454 | MEDIUM | 5.3 | 0.4% | Dec 27, 2024 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0... |
| CVE-2024-54453 | HIGH | 7.5 | 0.6% | Dec 27, 2024 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0... |
| CVE-2024-54452 | MEDIUM | 4.9 | 0.8% | Dec 27, 2024 | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35 and 7.10.x through 7.10.0.18. A Directory Traversal ... |
| CVE-2024-54451 | MEDIUM | 4.8 | 0.3% | Dec 27, 2024 | A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page in Kurmi Provisioning Suite before 7.9.0.... |
| CVE-2024-54450 | CRITICAL | 9.4 | 0.5% | Dec 27, 2024 | An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentica... |
| CVE-2024-39025 | HIGH | 7.5 | 0.4% | Dec 27, 2024 | Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data. |
| CVE-2024-12991 | MEDIUM | 5.3 | 0.3% | Dec 27, 2024 | A vulnerability was found in Beijing Longda Jushang Technology DBShop商城系统 3.3 Release 231225. It has been declared as pr... |
| CVE-2024-53476 | MEDIUM | 5.9 | 0.6% | Dec 27, 2024 | A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to b... |
| CVE-2024-50945 | HIGH | 7.5 | 0.6% | Dec 27, 2024 | An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, all... |
| CVE-2024-50944 | CRITICAL | 9.8 | 1.0% | Dec 27, 2024 | Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shoppin... |
| CVE-2024-12990 | MEDIUM | 5.3 | 0.3% | Dec 27, 2024 | A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown ... |
| CVE-2024-12989 | MEDIUM | 6.9 | 0.4% | Dec 27, 2024 | A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is s... |
| CVE-2024-12988 | HIGH | 7.5 | 0.8% | Dec 27, 2024 | A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulne... |
| CVE-2024-56509 | HIGH | 8.6 | 0.7% | Dec 27, 2024 | changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se... |
| CVE-2024-56508 | HIGH | 7.6 | 0.4% | Dec 27, 2024 | LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerabilit... |
| CVE-2024-56507 | MEDIUM | 5.4 | 0.3% | Dec 27, 2024 | LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a reflected cross-site scr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now