2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11842 | MEDIUM | 4.3 | 0.2% | Dec 27, 2024 | The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating it... |
| CVE-2024-11645 | MEDIUM | 4.8 | 0.3% | Dec 27, 2024 | The float block WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2024-11644 | MEDIUM | 5.9 | 0.3% | Dec 27, 2024 | The WP-SVG WordPress plugin through 0.9 does not validate and escape some of its shortcode attributes before outputting ... |
| CVE-2024-11605 | MEDIUM | 4.8 | 1.2% | Dec 27, 2024 | The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, whic... |
| CVE-2024-56522 | HIGH | 7.5 | 0.6% | Dec 27, 2024 | An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a con... |
| CVE-2024-56521 | CRITICAL | 9.8 | 0.7% | Dec 27, 2024 | An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are... |
| CVE-2024-56520 | HIGH | 7.3 | 0.5% | Dec 27, 2024 | An issue was discovered in tc-lib-pdf-font before 2.6.4, as used in TCPDF before 6.8.0 and other products. Fonts are mis... |
| CVE-2024-56519 | HIGH | 7.5 | 0.6% | Dec 27, 2024 | An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute. |
| CVE-2024-12980 | MEDIUM | 6.1 | 0.5% | Dec 27, 2024 | A vulnerability was found in code-projects Job Recruitment 1.0. It has been classified as problematic. Affected is the f... |
| CVE-2024-12979 | MEDIUM | 6.1 | 0.5% | Dec 27, 2024 | A vulnerability was found in code-projects Job Recruitment 1.0 and classified as problematic. This issue affects the fun... |
| CVE-2024-12978 | HIGH | 7.5 | 0.7% | Dec 27, 2024 | A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. This vulnerability affec... |
| CVE-2024-9774 | MEDIUM | 6.5 | 0.7% | Dec 27, 2024 | A vulnerability was found in python-sql where unary operators do not escape non-Expression. |
| CVE-2024-12977 | CRITICAL | 9.8 | 0.5% | Dec 27, 2024 | A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 1.0. This affects... |
| CVE-2024-12976 | CRITICAL | 9.8 | 0.6% | Dec 27, 2024 | A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected b... |
| CVE-2024-12969 | CRITICAL | 9.8 | 0.6% | Dec 26, 2024 | A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affec... |
| CVE-2024-56361 | MEDIUM | 5.3 | 0.4% | Dec 26, 2024 | LGSL (Live Game Server List) provides online status for games. Before 7.0.0, a stored cross-site scripting (XSS) vulnera... |
| CVE-2024-55950 | HIGH | 8.6 | 0.3% | Dec 26, 2024 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains... |
| CVE-2024-53850 | HIGH | 8.2 | 0.5% | Dec 26, 2024 | The Addressing GLPI plugin enables you to create IP reports for visualize IP addresses used and free on a given network.... |
| CVE-2024-45805 | MEDIUM | 4.3 | 0.3% | Dec 26, 2024 | OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access information that ca... |
| CVE-2024-45600 | HIGH | 7.7 | 0.5% | Dec 26, 2024 | Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated u... |
| CVE-2024-12968 | CRITICAL | 9.8 | 0.6% | Dec 26, 2024 | A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. Affected by this vulnerability is... |
| CVE-2024-12967 | CRITICAL | 9.8 | 0.6% | Dec 26, 2024 | A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. Affected is the function fln... |
| CVE-2024-56510 | MEDIUM | 5.3 | 0.3% | Dec 26, 2024 | @marp-team/marp-core is the core for Marp, which is the ecosystem to write your presentation with plain Markdown. Marp C... |
| CVE-2024-12966 | CRITICAL | 9.8 | 0.6% | Dec 26, 2024 | A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the fu... |
| CVE-2024-12965 | CRITICAL | 9.8 | 0.6% | Dec 26, 2024 | A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been declared as critical. This v... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now