2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56112 | MEDIUM | 6.1 | 0.2% | Dec 16, 2024 | CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php. |
| CVE-2024-56087 | MEDIUM | 5.9 | 0.3% | Dec 16, 2024 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template... |
| CVE-2024-56086 | HIGH | 7.1 | 0.4% | Dec 16, 2024 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are... |
| CVE-2024-56085 | MEDIUM | 5.9 | 0.3% | Dec 16, 2024 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template... |
| CVE-2024-56084 | HIGH | 7.1 | 0.3% | Dec 16, 2024 | An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while crea... |
| CVE-2024-11841 | MEDIUM | 5.4 | 0.3% | Dec 16, 2024 | The Tithe.ly Giving Button WordPress plugin through 1.1 does not validate and escape some of its shortcode attributes be... |
| CVE-2024-8650 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6... |
| CVE-2024-8116 | MEDIUM | 5.3 | 0.4% | Dec 16, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.... |
| CVE-2024-53376 | HIGH | 8.8 | 10.8% | Dec 16, 2024 | CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ... |
| CVE-2024-56083 | HIGH | 8.1 | 0.5% | Dec 16, 2024 | Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly... |
| CVE-2024-8798 | MEDIUM | 6.5 | 0.4% | Dec 16, 2024 | No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.... |
| CVE-2024-11858 | HIGH | 7.8 | 0.8% | Dec 15, 2024 | A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation wh... |
| CVE-2024-7701 | HIGH | 7.5 | 0.2% | Dec 15, 2024 | Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption B... |
| CVE-2024-56082 | LOW | 3.5 | 0.4% | Dec 15, 2024 | ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disab... |
| CVE-2024-56074 | MEDIUM | 5.5 | 0.3% | Dec 15, 2024 | gitingest before 9996a06 mishandles symbolic links that point outside of the base directory. |
| CVE-2024-55969 | CRITICAL | 9.1 | 0.6% | Dec 15, 2024 | DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX do... |
| CVE-2024-56073 | HIGH | 7.5 | 0.6% | Dec 15, 2024 | An issue was discovered in FastNetMon Community Edition through 1.2.7. Zero-length templates for Netflow v9 allow remote... |
| CVE-2024-56072 | HIGH | 7.5 | 0.7% | Dec 15, 2024 | An issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to ca... |
| CVE-2024-55970 | HIGH | 7.5 | 0.5% | Dec 15, 2024 | File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the ... |
| CVE-2024-31892 | HIGH | 7.5 | 0.3% | Dec 14, 2024 | IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 could allow a user to perform unauthorized act... |
| CVE-2024-31891 | HIGH | 7.8 | 0.2% | Dec 14, 2024 | IBM Storage Scale GUI 5.1.9.0 through 5.1.9.6 and 5.2.0.0 through 5.2.1.1 contains a local privilege escalation vulner... |
| CVE-2024-11721 | HIGH | 8.1 | 0.5% | Dec 14, 2024 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i... |
| CVE-2024-11720 | MEDIUM | 6.1 | 0.3% | Dec 14, 2024 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms ... |
| CVE-2024-12628 | MEDIUM | 4.4 | 0.4% | Dec 14, 2024 | The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' paramete... |
| CVE-2024-12446 | MEDIUM | 6.4 | 0.3% | Dec 14, 2024 | The Post to Pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gmptp_single_post' s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now