2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12943 | CRITICAL | 9.8 | 0.6% | Dec 26, 2024 | A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by... |
| CVE-2024-12942 | CRITICAL | 9.8 | 0.6% | Dec 26, 2024 | A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been classified as critical. Affe... |
| CVE-2024-12940 | CRITICAL | 9.8 | 0.7% | Dec 26, 2024 | A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Th... |
| CVE-2024-12938 | CRITICAL | 9.1 | 0.5% | Dec 26, 2024 | A vulnerability has been found in code-projects Simple Admin Panel 1.0 and classified as critical. Affected by this vuln... |
| CVE-2024-12936 | CRITICAL | 9.8 | 0.5% | Dec 26, 2024 | A vulnerability, which was classified as critical, has been found in code-projects Simple Admin Panel 1.0. This issue af... |
| CVE-2024-12935 | CRITICAL | 9.8 | 0.5% | Dec 26, 2024 | A vulnerability classified as critical was found in code-projects Simple Admin Panel 1.0. This vulnerability affects unk... |
| CVE-2024-12927 | CRITICAL | 9.8 | 0.6% | Dec 25, 2024 | A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System... |
| CVE-2024-56431 | CRITICAL | 9.8 | 1.8% | Dec 25, 2024 | oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: th... |
| CVE-2024-39727 | CRITICAL | 9.8 | 0.3% | Dec 25, 2024 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references ... |
| CVE-2024-8950 | CRITICAL | 9.9 | 0.6% | Dec 25, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics P... |
| CVE-2024-52046 | CRITICAL | 9.8 | 23.9% | Dec 25, 2024 | The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized... |
| CVE-2024-11281 | CRITICAL | 9.8 | 1.5% | Dec 25, 2024 | The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and incl... |
| CVE-2024-43441 | CRITICAL | 9.8 | 69.7% | Dec 24, 2024 | Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache Hug... |
| CVE-2024-40896 | CRITICAL | 9.1 | 1.2% | Dec 23, 2024 | In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for externa... |
| CVE-2024-54148 | CRITICAL | 9.8 | 0.8% | Dec 23, 2024 | Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a ... |
| CVE-2024-12900 | CRITICAL | 9.8 | 0.7% | Dec 23, 2024 | A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /... |
| CVE-2024-46873 | CRITICAL | 9.8 | 0.7% | Dec 23, 2024 | Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root pr... |
| CVE-2024-12899 | CRITICAL | 9.8 | 0.6% | Dec 23, 2024 | A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. Thi... |
| CVE-2024-12898 | CRITICAL | 9.8 | 0.5% | Dec 23, 2024 | A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been declared as critical. ... |
| CVE-2024-12895 | CRITICAL | 9.8 | 0.5% | Dec 22, 2024 | A vulnerability has been found in TreasureHuntGame TreasureHunt up to 963e0e0 and classified as critical. Affected by th... |
| CVE-2024-12894 | CRITICAL | 9.8 | 0.5% | Dec 22, 2024 | A vulnerability, which was classified as critical, was found in TreasureHuntGame TreasureHunt up to 963e0e0. Affected is... |
| CVE-2024-12884 | CRITICAL | 9.8 | 0.8% | Dec 21, 2024 | A vulnerability was found in Codezips E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is s... |
| CVE-2024-11349 | CRITICAL | 9.8 | 1.2% | Dec 21, 2024 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. Thi... |
| CVE-2024-55509 | CRITICAL | 9.8 | 0.8% | Dec 20, 2024 | SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary... |
| CVE-2024-56333 | CRITICAL | 9.4 | 0.6% | Dec 20, 2024 | Onyxia is a web app that aims at being the glue between multiple open source backend technologies to provide a state of ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now