2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-55878 | MEDIUM | 6.8 | 0.4% | Dec 12, 2024 | SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to ve... |
| CVE-2024-55877 | HIGH | 8.8 | 1.6% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5... |
| CVE-2024-55876 | MEDIUM | 5.4 | 0.6% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0,... |
| CVE-2024-55875 | CRITICAL | 9.8 | 1.9% | Dec 12, 2024 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML Ex... |
| CVE-2024-55663 | CRITICAL | 9.8 | 0.7% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc... |
| CVE-2024-54811 | CRITICAL | 9.8 | 0.6% | Dec 12, 2024 | A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to ex... |
| CVE-2024-49147 | CRITICAL | 9.8 | 1.3% | Dec 12, 2024 | Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on t... |
| CVE-2024-49071 | MEDIUM | 6.5 | 1.1% | Dec 12, 2024 | Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender al... |
| CVE-2024-55662 | HIGH | 8.8 | 0.7% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0,... |
| CVE-2024-54810 | CRITICAL | 9.8 | 1.0% | Dec 12, 2024 | A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment Sy... |
| CVE-2024-47238 | MEDIUM | 6.7 | 0.2% | Dec 12, 2024 | Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A hi... |
| CVE-2024-31670 | MEDIUM | 6.3 | 0.3% | Dec 12, 2024 | rizin before v0.6.3 is vulnerable to Buffer Overflow via create_cache_bins, read_cache_accel, and rz_dyldcache_new_buf f... |
| CVE-2024-55099 | CRITICAL | 9.8 | 1.0% | Dec 12, 2024 | A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows ... |
| CVE-2024-52901 | MEDIUM | 6.5 | 0.5% | Dec 12, 2024 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to GUI to not load or stop working due to impro... |
| CVE-2024-55633 | MEDIUM | 6.5 | 2.6% | Dec 12, 2024 | Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access c... |
| CVE-2024-54842 | CRITICAL | 9.8 | 0.5% | Dec 12, 2024 | A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php vi... |
| CVE-2024-21575 | CRITICAL | 9.2 | 1.0% | Dec 12, 2024 | ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` fie... |
| CVE-2024-50584 | MEDIUM | 4.4 | 0.3% | Dec 12, 2024 | An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_i... |
| CVE-2024-28146 | HIGH | 8.4 | 0.3% | Dec 12, 2024 | The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware d... |
| CVE-2024-28145 | MEDIUM | 5.9 | 0.5% | Dec 12, 2024 | An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malici... |
| CVE-2024-28144 | MEDIUM | 5.5 | 0.2% | Dec 12, 2024 | An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaw... |
| CVE-2024-28143 | HIGH | 8.4 | 0.3% | Dec 12, 2024 | The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vu... |
| CVE-2024-54122 | MEDIUM | 4.7 | 0.1% | Dec 12, 2024 | Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may... |
| CVE-2024-54119 | HIGH | 7.5 | 0.2% | Dec 12, 2024 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability... |
| CVE-2024-54118 | — | — | — | Dec 12, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now