2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56330 | CRITICAL | 9.3 | 0.5% | Dec 20, 2024 | Stardust is a platform for streaming isolated desktop containers. With this exploit, inter container communication (ICC)... |
| CVE-2024-56337 | CRITICAL | 9.8 | 8.9% | Dec 20, 2024 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: fro... |
| CVE-2024-51466 | CRITICAL | 9 | 0.6% | Dec 20, 2024 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL)... |
| CVE-2024-12571 | CRITICAL | 9.8 | 0.9% | Dec 20, 2024 | The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclus... |
| CVE-2024-56327 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crat... |
| CVE-2024-54984 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this... |
| CVE-2024-54983 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message. |
| CVE-2024-12728 | CRITICAL | 9.8 | 0.9% | Dec 19, 2024 | A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than versi... |
| CVE-2024-12727 | CRITICAL | 9.8 | 1.4% | Dec 19, 2024 | A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (... |
| CVE-2024-49765 | CRITICAL | 9.1 | 0.4% | Dec 19, 2024 | Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have loc... |
| CVE-2024-54150 | CRITICAL | 9.1 | 0.4% | Dec 19, 2024 | cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type o... |
| CVE-2024-12794 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | A vulnerability, which was classified as critical, was found in Codezips E-Commerce Site 1.0. This affects an unknown pa... |
| CVE-2024-12792 | CRITICAL | 9.8 | 0.6% | Dec 19, 2024 | A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an u... |
| CVE-2024-12791 | CRITICAL | 9.8 | 0.6% | Dec 19, 2024 | A vulnerability was found in Codezips E-Commerce Site 1.0. It has been rated as critical. This issue affects some unknow... |
| CVE-2024-55081 | CRITICAL | 9.8 | 0.8% | Dec 19, 2024 | An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attacker... |
| CVE-2024-12789 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of t... |
| CVE-2024-12788 | CRITICAL | 9.8 | 0.8% | Dec 19, 2024 | A vulnerability was found in Codezips Technical Discussion Forum 1.0 and classified as critical. Affected by this issue ... |
| CVE-2024-12787 | CRITICAL | 9.8 | 0.6% | Dec 19, 2024 | A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Af... |
| CVE-2024-12784 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been classified as critical. Affected is... |
| CVE-2024-10244 | CRITICAL | 9.8 | 0.5% | Dec 19, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web ... |
| CVE-2024-12626 | CRITICAL | 9.6 | 0.7% | Dec 19, 2024 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP... |
| CVE-2024-11984 | CRITICAL | 9.4 | 0.7% | Dec 19, 2024 | A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Managemen... |
| CVE-2024-55461 | CRITICAL | 9.8 | 1.1% | Dec 18, 2024 | SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext(). |
| CVE-2024-43106 | CRITICAL | 9.1 | 0.7% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Ex... |
| CVE-2024-42220 | CRITICAL | 9.1 | 0.7% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverag... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now