2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54102 | MEDIUM | 5.9 | 0.1% | Dec 12, 2024 | Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability may affect service ... |
| CVE-2024-54101 | MEDIUM | 5.5 | 0.1% | Dec 12, 2024 | Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability w... |
| CVE-2024-54100 | HIGH | 7.5 | 0.2% | Dec 12, 2024 | Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerabilit... |
| CVE-2024-54099 | HIGH | 7.1 | 0.1% | Dec 12, 2024 | File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability will affect integri... |
| CVE-2024-54098 | HIGH | 7.5 | 0.2% | Dec 12, 2024 | Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may... |
| CVE-2024-54097 | HIGH | 7.5 | 0.3% | Dec 12, 2024 | Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature imp... |
| CVE-2024-54096 | MEDIUM | 5.5 | 0.1% | Dec 12, 2024 | Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may aff... |
| CVE-2024-12570 | MEDIUM | 6.7 | 0.4% | Dec 12, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior ... |
| CVE-2024-12292 | MEDIUM | 4 | 0.2% | Dec 12, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 pr... |
| CVE-2024-11274 | HIGH | 8.7 | 0.5% | Dec 12, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 pr... |
| CVE-2024-10043 | LOW | 3.1 | 0.4% | Dec 12, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting... |
| CVE-2024-4109 | — | — | — | Dec 12, 2024 | Rejected reason: Red Hat Product Security has determined that this CVE is not a security vulnerability. |
| CVE-2024-21574 | CRITICAL | 10 | 1.1% | Dec 12, 2024 | The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint us... |
| CVE-2024-12401 | MEDIUM | 4.4 | 0.6% | Dec 12, 2024 | A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager... |
| CVE-2024-12397 | HIGH | 7.4 | 0.8% | Dec 12, 2024 | A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming ... |
| CVE-2024-12333 | MEDIUM | 6.5 | 0.4% | Dec 12, 2024 | The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.... |
| CVE-2024-12160 | MEDIUM | 6.1 | 0.4% | Dec 12, 2024 | The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due ... |
| CVE-2024-11760 | MEDIUM | 6.4 | 0.3% | Dec 12, 2024 | The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '... |
| CVE-2024-12564 | MEDIUM | 6.9 | 0.6% | Dec 12, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWE... |
| CVE-2024-12329 | MEDIUM | 4.3 | 0.3% | Dec 12, 2024 | The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2024-12312 | HIGH | 8.1 | 1.1% | Dec 12, 2024 | The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi... |
| CVE-2024-12201 | MEDIUM | 4.3 | 0.4% | Dec 12, 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capa... |
| CVE-2024-11727 | MEDIUM | 4.4 | 0.3% | Dec 12, 2024 | The NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating... |
| CVE-2024-11724 | MEDIUM | 4.3 | 0.3% | Dec 12, 2024 | The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plug... |
| CVE-2024-11181 | MEDIUM | 4.3 | 0.5% | Dec 12, 2024 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Information Exposure in all ver... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now