2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11358 | MEDIUM | 5.5 | 0.1% | Dec 16, 2024 | Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with... |
| CVE-2024-11144 | CRITICAL | 9.2 | 0.3% | Dec 16, 2024 | The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The... |
| CVE-2024-10095 | CRITICAL | 9.8 | 0.7% | Dec 16, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an i... |
| CVE-2024-56003 | MEDIUM | 4.3 | 0.3% | Dec 16, 2024 | Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer caldera-smtp-mailer.This issue affects Caldera S... |
| CVE-2024-55999 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in Marco Giannini XML Multilanguage Sitemap Generator xml-multilanguage-sitemap-gene... |
| CVE-2024-54376 | HIGH | 7.5 | 0.6% | Dec 16, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-54357 | MEDIUM | 4.3 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <=... |
| CVE-2024-54348 | MEDIUM | 6.5 | 0.2% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yaycommerce Brand ... |
| CVE-2024-54285 | CRITICAL | 9.1 | 0.5% | Dec 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to ... |
| CVE-2024-54284 | HIGH | 7.6 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedP... |
| CVE-2024-54283 | HIGH | 7.6 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedP... |
| CVE-2024-54280 | CRITICAL | 9.8 | 0.6% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBo... |
| CVE-2024-54279 | HIGH | 7.5 | 0.5% | Dec 16, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tobias Keller WP-NERD Toolki... |
| CVE-2024-54257 | HIGH | 7.1 | 0.3% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molefed allows Ref... |
| CVE-2024-54249 | HIGH | 7.1 | 0.3% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jules Colle Advanc... |
| CVE-2024-54229 | CRITICAL | 9.8 | 0.4% | Dec 16, 2024 | Incorrect Privilege Assignment vulnerability in straightvisions GmbH SV100 Companion sv100-companion allows Privilege Es... |
| CVE-2024-43234 | CRITICAL | 9.8 | 0.6% | Dec 16, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authenticatio... |
| CVE-2024-12654 | MEDIUM | 5.5 | 0.3% | Dec 16, 2024 | A vulnerability classified as problematic was found in FabulaTech USB over Network 6.0.6.1. Affected by this vulnerabili... |
| CVE-2024-12653 | MEDIUM | 5.5 | 0.4% | Dec 16, 2024 | A vulnerability classified as problematic has been found in FabulaTech USB over Network 6.0.6.1. Affected is the functio... |
| CVE-2024-56015 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in John Godley Tidy Up allows Reflected XSS.This issue affects Tidy Up: ... |
| CVE-2024-56013 | HIGH | 8.8 | 0.6% | Dec 16, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in wovax Wovax IDX wovax-idx allows Authenticatio... |
| CVE-2024-56012 | CRITICAL | 9.8 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Flash News / Post (Responsive) flashnews-fading-effect-pearlb... |
| CVE-2024-56011 | MEDIUM | 6.5 | 0.3% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilja Zaglov Respon... |
| CVE-2024-56009 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality... |
| CVE-2024-56007 | MEDIUM | 4.3 | 0.3% | Dec 16, 2024 | Missing Authorization vulnerability in leader codes Leader leader allows Exploiting Incorrectly Configured Access Contro... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now