2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9101 | LOW | 2.1 | 0.5% | Dec 19, 2024 | A reflected cross-site scripting (XSS) vulnerability in the 'Entry Chooser' of phpLDAPadmin (version 1.2.1 through the l... |
| CVE-2024-12784 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been classified as critical. Affected is... |
| CVE-2024-10244 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web ... |
| CVE-2024-12783 | MEDIUM | 6.1 | 0.4% | Dec 19, 2024 | A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affect... |
| CVE-2024-12782 | HIGH | 7.3 | 0.7% | Dec 19, 2024 | A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 an... |
| CVE-2024-45819 | MEDIUM | 5.5 | 0.3% | Dec 19, 2024 | PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local ... |
| CVE-2024-45818 | MEDIUM | 6.5 | 0.2% | Dec 19, 2024 | The hypervisor contains code to accelerate VGA memory accesses for HVM guests, when the (virtual) VGA is in "standard" m... |
| CVE-2024-37962 | MEDIUM | 6.5 | 0.2% | Dec 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion In... |
| CVE-2024-12626 | CRITICAL | 9.6 | 0.7% | Dec 19, 2024 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP... |
| CVE-2024-12331 | MEDIUM | 4.3 | 0.3% | Dec 19, 2024 | The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2024-11616 | MEDIUM | 5.6 | 0.3% | Dec 19, 2024 | Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fet... |
| CVE-2024-12569 | HIGH | 7.8 | 0.1% | Dec 19, 2024 | Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allow... |
| CVE-2024-4230 | HIGH | 7.8 | 0.2% | Dec 19, 2024 | External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and ... |
| CVE-2024-4229 | HIGH | 7.8 | 0.2% | Dec 19, 2024 | Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecros... |
| CVE-2024-12560 | MEDIUM | 6.5 | 0.4% | Dec 19, 2024 | The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Inf... |
| CVE-2024-11768 | MEDIUM | 5.3 | 0.3% | Dec 19, 2024 | The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to im... |
| CVE-2024-11740 | HIGH | 7.3 | 1.9% | Dec 19, 2024 | The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and ... |
| CVE-2024-11984 | CRITICAL | 9.4 | 0.7% | Dec 19, 2024 | A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Managemen... |
| CVE-2024-51532 | HIGH | 7.1 | 0.3% | Dec 19, 2024 | Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerabi... |
| CVE-2024-35141 | HIGH | 7.8 | 0.2% | Dec 19, 2024 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to exe... |
| CVE-2024-12121 | MEDIUM | 5.4 | 0.3% | Dec 19, 2024 | The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions... |
| CVE-2024-10548 | MEDIUM | 6.5 | 0.4% | Dec 19, 2024 | The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i... |
| CVE-2024-55603 | MEDIUM | 6.5 | 0.5% | Dec 19, 2024 | Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still ... |
| CVE-2024-56319 | HIGH | 7.5 | 0.5% | Dec 18, 2024 | In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userla... |
| CVE-2024-56318 | HIGH | 7.5 | 0.6% | Dec 18, 2024 | In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer d... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now