2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54352 | HIGH | 8.8 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Sabri Sogrid sogrid allows Privilege Escalation.This issue affects So... |
| CVE-2024-54332 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WPFactory WP Currency Exchange Rates wp-currency-exchange-rates allow... |
| CVE-2024-54331 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Micha I Plant A Tree i-plant-a-tree allows Stored XSS.This issue affe... |
| CVE-2024-49775 | CRITICAL | 9.8 | 1.5% | Dec 16, 2024 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence ... |
| CVE-2024-37251 | MEDIUM | 4.3 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced... |
| CVE-2024-12668 | HIGH | 8.2 | 0.2% | Dec 16, 2024 | Velocidex WinPmem versions below 4.1 suffer from an Out of Bounds Write vulnerability. By using an IO Control, a user sp... |
| CVE-2024-12092 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE... |
| CVE-2024-12091 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER... |
| CVE-2024-12090 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE... |
| CVE-2024-12089 | MEDIUM | 5.4 | 0.4% | Dec 16, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER... |
| CVE-2024-10972 | HIGH | 7.3 | 0.2% | Dec 16, 2024 | Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with... |
| CVE-2024-12478 | HIGH | 8.8 | 0.5% | Dec 16, 2024 | A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the ... |
| CVE-2024-12362 | MEDIUM | 5.3 | 0.5% | Dec 16, 2024 | A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function ... |
| CVE-2024-54682 | MEDIUM | 4.9 | 0.4% | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size fo... |
| CVE-2024-54083 | MEDIUM | 6.5 | 0.6% | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the ... |
| CVE-2024-48872 | MEDIUM | 4.8 | 0.2% | Dec 16, 2024 | Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrent... |
| CVE-2024-9679 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | A Hardcoded Cryptographic key vulnerability existed in DLP Extension 11.11.1.3 which allowed the decryption of previousl... |
| CVE-2024-9678 | MEDIUM | 4.9 | 0.7% | Dec 16, 2024 | An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arb... |
| CVE-2024-12646 | HIGH | 8.1 | 0.3% | Dec 16, 2024 | The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local... |
| CVE-2024-12645 | MEDIUM | 6.5 | 0.3% | Dec 16, 2024 | The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local w... |
| CVE-2024-12644 | HIGH | 7.1 | 0.3% | Dec 16, 2024 | The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web ser... |
| CVE-2024-12643 | HIGH | 8.1 | 0.3% | Dec 16, 2024 | The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local ... |
| CVE-2024-12642 | HIGH | 8.1 | 0.3% | Dec 16, 2024 | TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple loca... |
| CVE-2024-12641 | CRITICAL | 9.6 | 1.4% | Dec 16, 2024 | TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a si... |
| CVE-2024-5333 | MEDIUM | 5.3 | 1.1% | Dec 16, 2024 | The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticat... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now