2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8950 | CRITICAL | 9.9 | 0.6% | Dec 25, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics P... |
| CVE-2024-52046 | CRITICAL | 9.8 | 23.9% | Dec 25, 2024 | The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized... |
| CVE-2024-12335 | MEDIUM | 4.3 | 0.4% | Dec 25, 2024 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi... |
| CVE-2024-11281 | CRITICAL | 9.8 | 1.5% | Dec 25, 2024 | The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and incl... |
| CVE-2024-10862 | MEDIUM | 4.9 | 0.6% | Dec 25, 2024 | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Injection ... |
| CVE-2024-10858 | MEDIUM | 6.1 | 0.3% | Dec 25, 2024 | The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing... |
| CVE-2024-12636 | MEDIUM | 4.3 | 0.2% | Dec 25, 2024 | The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul... |
| CVE-2024-12428 | HIGH | 7.5 | 0.5% | Dec 25, 2024 | The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via t... |
| CVE-2024-1609 | HIGH | 8.7 | 0.5% | Dec 25, 2024 | In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation. |
| CVE-2024-12413 | MEDIUM | 5.3 | 0.4% | Dec 25, 2024 | The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorize... |
| CVE-2024-12272 | HIGH | 8.8 | 0.7% | Dec 25, 2024 | The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPr... |
| CVE-2024-12190 | MEDIUM | 4.3 | 0.4% | Dec 25, 2024 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
| CVE-2024-12032 | MEDIUM | 6.5 | 0.5% | Dec 25, 2024 | The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin f... |
| CVE-2024-12746 | HIGH | 8.6 | 0.4% | Dec 24, 2024 | A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privilege... |
| CVE-2024-12745 | HIGH | 8.6 | 0.5% | Dec 24, 2024 | A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_sc... |
| CVE-2024-12744 | HIGH | 8.6 | 0.6% | Dec 24, 2024 | A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSc... |
| CVE-2024-53163 | MEDIUM | 5.5 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_420xx - fix off by one in uof_get_n... |
| CVE-2024-53162 | HIGH | 7.1 | 0.3% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_4xxx - fix off by one in uof_get_na... |
| CVE-2024-53161 | MEDIUM | 5.5 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: EDAC/bluefield: Fix potential integer overflow The... |
| CVE-2024-53160 | MEDIUM | 4.7 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: rcu/kvfree: Fix data-race in __mod_timer / kvfree_c... |
| CVE-2024-53159 | — | — | — | Dec 24, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-53158 | MEDIUM | 5.5 | 0.3% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: soc: qcom: geni-se: fix array underflow in geni_se_... |
| CVE-2024-53157 | MEDIUM | 5.5 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scpi: Check the DVFS OPP count return... |
| CVE-2024-53156 | HIGH | 7.8 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: add range check for conn_rsp_epid in h... |
| CVE-2024-53155 | HIGH | 7.1 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now