2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54148 | CRITICAL | 9.8 | 0.8% | Dec 23, 2024 | Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a ... |
| CVE-2024-53256 | HIGH | 7.8 | 1.2% | Dec 23, 2024 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code ... |
| CVE-2024-45387 | HIGH | 8.8 | 41.8% | Dec 23, 2024 | An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with... |
| CVE-2024-23945 | MEDIUM | 5.9 | 1.5% | Dec 23, 2024 | Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authentici... |
| CVE-2024-55539 | LOW | 2.5 | 0.1% | Dec 23, 2024 | Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) ... |
| CVE-2024-12903 | HIGH | 7.8 | 0.2% | Dec 23, 2024 | Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could expl... |
| CVE-2024-12902 | HIGH | 8.4 | 0.2% | Dec 23, 2024 | ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows... |
| CVE-2024-11230 | MEDIUM | 5.4 | 0.3% | Dec 23, 2024 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ p... |
| CVE-2024-12901 | MEDIUM | 6.9 | 0.6% | Dec 23, 2024 | A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown funct... |
| CVE-2024-12900 | CRITICAL | 9.8 | 0.7% | Dec 23, 2024 | A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /... |
| CVE-2024-54082 | HIGH | 7.2 | 1.2% | Dec 23, 2024 | home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore functio... |
| CVE-2024-52321 | MEDIUM | 5.9 | 0.5% | Dec 23, 2024 | Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The produc... |
| CVE-2024-47864 | MEDIUM | 5.3 | 0.6% | Dec 23, 2024 | home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug... |
| CVE-2024-46873 | CRITICAL | 9.8 | 0.7% | Dec 23, 2024 | Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root pr... |
| CVE-2024-45721 | HIGH | 7.2 | 1.2% | Dec 23, 2024 | home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST n... |
| CVE-2024-12899 | CRITICAL | 9.8 | 0.6% | Dec 23, 2024 | A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. Thi... |
| CVE-2024-12898 | CRITICAL | 9.8 | 0.5% | Dec 23, 2024 | A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been declared as critical. ... |
| CVE-2024-56378 | MEDIUM | 4.3 | 0.6% | Dec 23, 2024 | libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine functio... |
| CVE-2024-12897 | MEDIUM | 5.3 | 0.5% | Dec 23, 2024 | A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has ... |
| CVE-2024-56375 | HIGH | 7.5 | 0.4% | Dec 22, 2024 | An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from... |
| CVE-2024-12896 | MEDIUM | 6.9 | 0.5% | Dec 22, 2024 | A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and clas... |
| CVE-2024-56314 | MEDIUM | 5.4 | 0.4% | Dec 22, 2024 | A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated user... |
| CVE-2024-56313 | MEDIUM | 5.4 | 0.4% | Dec 22, 2024 | A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated ... |
| CVE-2024-56312 | MEDIUM | 5.4 | 0.4% | Dec 22, 2024 | A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenti... |
| CVE-2024-56311 | HIGH | 8.8 | 0.3% | Dec 22, 2024 | REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Reques... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now