2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10476 | HIGH | 8 | 0.2% | Dec 17, 2024 | Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be ab... |
| CVE-2024-37607 | MEDIUM | 6.5 | 0.5% | Dec 17, 2024 | A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Servi... |
| CVE-2024-37606 | MEDIUM | 6.5 | 0.5% | Dec 17, 2024 | A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (D... |
| CVE-2024-37605 | MEDIUM | 6.5 | 0.6% | Dec 17, 2024 | A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service ... |
| CVE-2024-36832 | HIGH | 7.5 | 0.4% | Dec 17, 2024 | A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via... |
| CVE-2024-36831 | MEDIUM | 5.3 | 0.7% | Dec 17, 2024 | A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02... |
| CVE-2024-8972 | CRITICAL | 9.8 | 0.4% | Dec 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobil365 Informati... |
| CVE-2024-9819 | MEDIUM | 6.5 | 0.4% | Dec 17, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse.... |
| CVE-2024-54677 | MEDIUM | 5.3 | 1.9% | Dec 17, 2024 | Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to den... |
| CVE-2024-50379 | CRITICAL | 9.8 | 42.3% | Dec 17, 2024 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE o... |
| CVE-2024-10356 | MEDIUM | 4.3 | 0.4% | Dec 17, 2024 | The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi... |
| CVE-2024-9654 | LOW | 3.7 | 0.3% | Dec 17, 2024 | The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. T... |
| CVE-2024-8475 | MEDIUM | 6.5 | 0.4% | Dec 17, 2024 | Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulati... |
| CVE-2024-8429 | MEDIUM | 4.3 | 0.4% | Dec 17, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows ... |
| CVE-2024-52542 | MEDIUM | 5.5 | 0.2% | Dec 17, 2024 | Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with... |
| CVE-2024-12601 | MEDIUM | 5.3 | 0.5% | Dec 17, 2024 | The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including,... |
| CVE-2024-12395 | MEDIUM | 6.1 | 0.5% | Dec 17, 2024 | The WooCommerce Additional Fees On Checkout (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-11280 | MEDIUM | 5.3 | 0.4% | Dec 17, 2024 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions u... |
| CVE-2024-8326 | HIGH | 8.8 | 0.6% | Dec 17, 2024 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin... |
| CVE-2024-12469 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2024-12127 | MEDIUM | 6.1 | 0.3% | Dec 17, 2024 | The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vu... |
| CVE-2024-12024 | MEDIUM | 6.1 | 0.4% | Dec 17, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-12293 | HIGH | 8.8 | 0.3% | Dec 17, 2024 | The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2024-11294 | MEDIUM | 5.3 | 0.5% | Dec 17, 2024 | The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-12220 | MEDIUM | 6.1 | 0.2% | Dec 17, 2024 | The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now