2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45338 | MEDIUM | 5.3 | 0.9% | Dec 18, 2024 | An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, r... |
| CVE-2024-12686 | HIGH | 7.2 | 13.8% | Dec 18, 2024 | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacke... |
| CVE-2024-53271 | HIGH | 7.1 | 0.6% | Dec 18, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle... |
| CVE-2024-53270 | HIGH | 7.5 | 0.7% | Dec 18, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to... |
| CVE-2024-53269 | HIGH | 7.5 | 0.7% | Dec 18, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then t... |
| CVE-2024-52593 | MEDIUM | 5.3 | 0.4% | Dec 18, 2024 | Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService... |
| CVE-2024-52592 | MEDIUM | 5.3 | 0.3% | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.u... |
| CVE-2024-52591 | CRITICAL | 9.3 | 0.3% | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService... |
| CVE-2024-52590 | MEDIUM | 6.5 | 0.3% | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService... |
| CVE-2024-52579 | MEDIUM | 5.4 | 0.2% | Dec 18, 2024 | Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check t... |
| CVE-2024-51470 | MEDIUM | 6.5 | 0.5% | Dec 18, 2024 | IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE... |
| CVE-2024-49363 | HIGH | 7.4 | 0.3% | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in gith... |
| CVE-2024-36694 | HIGH | 7.2 | 0.9% | Dec 18, 2024 | OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function. |
| CVE-2024-12741 | HIGH | 8.4 | 4.2% | Dec 18, 2024 | A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Succ... |
| CVE-2024-56057 | HIGH | 8.8 | 0.5% | Dec 18, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell... |
| CVE-2024-56055 | HIGH | 8.8 | 0.5% | Dec 18, 2024 | Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLM... |
| CVE-2024-56054 | HIGH | 8.8 | 0.6% | Dec 18, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell... |
| CVE-2024-56053 | HIGH | 8.8 | 0.4% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS w... |
| CVE-2024-56052 | HIGH | 8.8 | 0.7% | Dec 18, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell... |
| CVE-2024-56051 | HIGH | 8.8 | 0.4% | Dec 18, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Inj... |
| CVE-2024-56050 | HIGH | 8.8 | 0.7% | Dec 18, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell... |
| CVE-2024-56049 | HIGH | 8.5 | 0.4% | Dec 18, 2024 | Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLM... |
| CVE-2024-56048 | HIGH | 8.8 | 0.6% | Dec 18, 2024 | Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constra... |
| CVE-2024-56047 | HIGH | 8.8 | 0.6% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS w... |
| CVE-2024-55953 | HIGH | 8.1 | 1.0% | Dec 18, 2024 | DataEase is an open source business analytics tool. Authenticated users can read and deserialize arbitrary files through... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now