2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12239 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navig... |
| CVE-2024-10205 | CRITICAL | 9.4 | 0.8% | Dec 17, 2024 | Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail ... |
| CVE-2024-11906 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The TPG Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpg_get_posts' sho... |
| CVE-2024-11905 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animatedcounte... |
| CVE-2024-11902 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations... |
| CVE-2024-11900 | MEDIUM | 6.4 | 0.3% | Dec 17, 2024 | The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-56017 | HIGH | 7.1 | 0.1% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects... |
| CVE-2024-55452 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of ... |
| CVE-2024-55451 | MEDIUM | 4.8 | 0.3% | Dec 16, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in U... |
| CVE-2024-55085 | CRITICAL | 9.8 | 0.8% | Dec 16, 2024 | GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background managem... |
| CVE-2024-35230 | MEDIUM | 5.3 | 0.7% | Dec 16, 2024 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affe... |
| CVE-2024-12443 | MEDIUM | 6.4 | 0.3% | Dec 16, 2024 | The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Sto... |
| CVE-2024-55554 | MEDIUM | 5.4 | 0.2% | Dec 16, 2024 | Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet. |
| CVE-2024-52949 | HIGH | 7.5 | 0.7% | Dec 16, 2024 | iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control th... |
| CVE-2024-37776 | MEDIUM | 4.8 | 0.3% | Dec 16, 2024 | A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scri... |
| CVE-2024-37775 | HIGH | 7.5 | 0.4% | Dec 16, 2024 | Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location wh... |
| CVE-2024-37774 | HIGH | 8 | 0.2% | Dec 16, 2024 | A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their priv... |
| CVE-2024-37773 | MEDIUM | 4.8 | 0.2% | Dec 16, 2024 | An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject... |
| CVE-2024-29671 | CRITICAL | 9.8 | 20.9% | Dec 16, 2024 | Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-55557 | CRITICAL | 9.8 | 1.3% | Dec 16, 2024 | ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credenti... |
| CVE-2024-55104 | HIGH | 7.2 | 0.5% | Dec 16, 2024 | Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin... |
| CVE-2024-55103 | HIGH | 7.2 | 0.6% | Dec 16, 2024 | Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.... |
| CVE-2024-55100 | MEDIUM | 4.8 | 0.3% | Dec 16, 2024 | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Online Nurse Hiring System v1.0... |
| CVE-2024-55951 | MEDIUM | 4.8 | 0.4% | Dec 16, 2024 | Metabase is an open-source data analytics platform. For new sandboxing configurations created in 1.52.0 till 1.52.2.4, s... |
| CVE-2024-55949 | CRITICAL | 9.3 | 0.7% | Dec 16, 2024 | MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a pr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now