2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9779 | HIGH | 7.5 | 0.4% | Dec 17, 2024 | A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-m... |
| CVE-2024-10973 | MEDIUM | 5.7 | 0.3% | Dec 17, 2024 | A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGr... |
| CVE-2024-56142 | MEDIUM | 6.5 | 0.4% | Dec 17, 2024 | pghoard is a PostgreSQL backup daemon and restore tooling that stores backup data in cloud object stores. A vulnerabilit... |
| CVE-2024-52792 | MEDIUM | 6.5 | 0.7% | Dec 17, 2024 | LDAP Account Manager (LAM) is a php webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LD... |
| CVE-2024-51175 | HIGH | 7.5 | 0.3% | Dec 17, 2024 | An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component. |
| CVE-2024-31668 | CRITICAL | 9.1 | 0.5% | Dec 17, 2024 | rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis... |
| CVE-2024-29646 | CRITICAL | 9.8 | 0.9% | Dec 17, 2024 | Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, typ... |
| CVE-2024-55059 | MEDIUM | 6.1 | 0.2% | Dec 17, 2024 | A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certifi... |
| CVE-2024-55058 | MEDIUM | 4.3 | 0.2% | Dec 17, 2024 | An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1... |
| CVE-2024-55057 | MEDIUM | 5.4 | 0.1% | Dec 17, 2024 | Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unautho... |
| CVE-2024-55056 | MEDIUM | 5.4 | 0.2% | Dec 17, 2024 | A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /u... |
| CVE-2024-12539 | MEDIUM | 6.5 | 0.4% | Dec 17, 2024 | An issue was discovered where improper authorization controls affected certain queries that could allow a malicious acto... |
| CVE-2024-11993 | MEDIUM | 6.1 | 0.3% | Dec 17, 2024 | Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA thro... |
| CVE-2024-55516 | CRITICAL | 9.1 | 0.5% | Dec 17, 2024 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issu... |
| CVE-2024-55515 | CRITICAL | 9.8 | 0.6% | Dec 17, 2024 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue... |
| CVE-2024-55514 | MEDIUM | 6.3 | 0.2% | Dec 17, 2024 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue... |
| CVE-2024-55513 | CRITICAL | 9.1 | 0.5% | Dec 17, 2024 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue... |
| CVE-2024-49194 | HIGH | 7.3 | 0.7% | Dec 17, 2024 | Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI inject... |
| CVE-2024-56139 | MEDIUM | 6.9 | 0.4% | Dec 17, 2024 | pdftools is a high level tools to convert PDF files to ePUB formats. In versions up to and including 0.5.0 maliciously c... |
| CVE-2024-51479 | HIGH | 7.5 | 3.9% | Dec 17, 2024 | Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is ... |
| CVE-2024-55496 | CRITICAL | 9.1 | 0.6% | Dec 17, 2024 | A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects... |
| CVE-2024-54662 | CRITICAL | 9.1 | 0.5% | Dec 17, 2024 | Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving soc... |
| CVE-2024-49820 | LOW | 3.7 | 0.2% | Dec 17, 2024 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensiti... |
| CVE-2024-49819 | HIGH | 7.5 | 0.3% | Dec 17, 2024 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensiti... |
| CVE-2024-49818 | MEDIUM | 4.3 | 0.5% | Dec 17, 2024 | IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now