2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42004 | CRITICAL | 9.8 | 0.8% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially... |
| CVE-2024-41165 | CRITICAL | 9.1 | 0.7% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Wor... |
| CVE-2024-41145 | CRITICAL | 9.8 | 0.8% | Dec 18, 2024 | A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.27... |
| CVE-2024-41138 | CRITICAL | 9.8 | 0.9% | Dec 18, 2024 | A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work ... |
| CVE-2024-39804 | CRITICAL | 9.1 | 0.9% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can levera... |
| CVE-2024-56145 | CRITICAL | 9.8 | 97.4% | Dec 18, 2024 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected ... |
| CVE-2024-52591 | CRITICAL | 9.3 | 0.3% | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService... |
| CVE-2024-54383 | CRITICAL | 9.8 | 1.1% | Dec 18, 2024 | Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege... |
| CVE-2024-12373 | CRITICAL | 9.3 | 0.5% | Dec 18, 2024 | A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a b... |
| CVE-2024-12372 | CRITICAL | 9.3 | 0.9% | Dec 18, 2024 | A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 100... |
| CVE-2024-12371 | CRITICAL | 9.3 | 0.5% | Dec 18, 2024 | A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configur... |
| CVE-2024-56059 | CRITICAL | 9.8 | 1.7% | Dec 18, 2024 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Pa... |
| CVE-2024-56058 | CRITICAL | 9.8 | 1.7% | Dec 18, 2024 | Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.Th... |
| CVE-2024-4996 | CRITICAL | 9.8 | 0.5% | Dec 18, 2024 | Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attack... |
| CVE-2024-4995 | CRITICAL | 9.8 | 0.9% | Dec 18, 2024 | Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt... |
| CVE-2024-1610 | CRITICAL | 9.8 | 0.7% | Dec 18, 2024 | In OPPO Store APP, there's a possible escalation of privilege due to improper input validation. |
| CVE-2024-12287 | CRITICAL | 9.8 | 0.6% | Dec 18, 2024 | The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includin... |
| CVE-2024-21546 | CRITICAL | 9.8 | 1.3% | Dec 18, 2024 | Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through ... |
| CVE-2024-31668 | CRITICAL | 9.1 | 0.5% | Dec 17, 2024 | rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis... |
| CVE-2024-29646 | CRITICAL | 9.8 | 0.9% | Dec 17, 2024 | Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, typ... |
| CVE-2024-55516 | CRITICAL | 9.1 | 0.5% | Dec 17, 2024 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issu... |
| CVE-2024-55515 | CRITICAL | 9.8 | 0.6% | Dec 17, 2024 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue... |
| CVE-2024-55513 | CRITICAL | 9.1 | 0.5% | Dec 17, 2024 | A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue... |
| CVE-2024-55496 | CRITICAL | 9.1 | 0.6% | Dec 17, 2024 | A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects... |
| CVE-2024-54662 | CRITICAL | 9.1 | 0.5% | Dec 17, 2024 | Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving soc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now