2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56317 | HIGH | 7.5 | 0.4% | Dec 18, 2024 | In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries ... |
| CVE-2024-56116 | HIGH | 8.8 | 0.4% | Dec 18, 2024 | A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator ... |
| CVE-2024-56115 | MEDIUM | 6.1 | 0.5% | Dec 18, 2024 | A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It ... |
| CVE-2024-55506 | HIGH | 8.8 | 0.7% | Dec 18, 2024 | An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to ex... |
| CVE-2024-55461 | CRITICAL | 9.8 | 1.1% | Dec 18, 2024 | SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext(). |
| CVE-2024-55239 | MEDIUM | 5.4 | 0.3% | Dec 18, 2024 | A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar... |
| CVE-2024-53580 | HIGH | 7.5 | 0.9% | Dec 18, 2024 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. |
| CVE-2024-43106 | CRITICAL | 9.1 | 0.7% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Ex... |
| CVE-2024-42220 | CRITICAL | 9.1 | 0.7% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverag... |
| CVE-2024-42004 | CRITICAL | 9.8 | 0.8% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially... |
| CVE-2024-41165 | CRITICAL | 9.1 | 0.7% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Wor... |
| CVE-2024-41159 | HIGH | 7.1 | 0.8% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage ... |
| CVE-2024-41145 | CRITICAL | 9.8 | 0.8% | Dec 18, 2024 | A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.27... |
| CVE-2024-41138 | CRITICAL | 9.8 | 0.9% | Dec 18, 2024 | A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work ... |
| CVE-2024-39804 | CRITICAL | 9.1 | 0.9% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can levera... |
| CVE-2024-37649 | MEDIUM | 4.6 | 0.3% | Dec 18, 2024 | Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proxi... |
| CVE-2024-55505 | HIGH | 8.8 | 0.7% | Dec 18, 2024 | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-vie... |
| CVE-2024-55232 | MEDIUM | 5.4 | 0.4% | Dec 18, 2024 | An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows un... |
| CVE-2024-55231 | MEDIUM | 4.3 | 0.3% | Dec 18, 2024 | An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unau... |
| CVE-2024-12695 | HIGH | 8.8 | 0.4% | Dec 18, 2024 | Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code i... |
| CVE-2024-12694 | HIGH | 8.8 | 0.3% | Dec 18, 2024 | Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit ... |
| CVE-2024-12693 | HIGH | 8.8 | 0.4% | Dec 18, 2024 | Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrar... |
| CVE-2024-12692 | HIGH | 8.8 | 6.1% | Dec 18, 2024 | Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2024-56145 | CRITICAL | 9.8 | 97.4% | Dec 18, 2024 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected ... |
| CVE-2024-56140 | MEDIUM | 6.5 | 0.2% | Dec 18, 2024 | Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now