2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8972 | CRITICAL | 9.8 | 0.4% | Dec 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobil365 Informati... |
| CVE-2024-50379 | CRITICAL | 9.8 | 42.3% | Dec 17, 2024 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE o... |
| CVE-2024-12356 | CRITICAL | 9.8 | 88.0% | Dec 17, 2024 | A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which ca... |
| CVE-2024-10205 | CRITICAL | 9.4 | 0.8% | Dec 17, 2024 | Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail ... |
| CVE-2024-55085 | CRITICAL | 9.8 | 0.8% | Dec 16, 2024 | GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background managem... |
| CVE-2024-29671 | CRITICAL | 9.8 | 20.9% | Dec 16, 2024 | Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-55557 | CRITICAL | 9.8 | 1.3% | Dec 16, 2024 | ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credenti... |
| CVE-2024-55949 | CRITICAL | 9.3 | 0.7% | Dec 16, 2024 | MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a pr... |
| CVE-2024-12687 | CRITICAL | 9.8 | 0.6% | Dec 16, 2024 | Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitra... |
| CVE-2024-11144 | CRITICAL | 9.2 | 0.3% | Dec 16, 2024 | The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The... |
| CVE-2024-10095 | CRITICAL | 9.8 | 0.7% | Dec 16, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an i... |
| CVE-2024-54285 | CRITICAL | 9.1 | 0.5% | Dec 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to ... |
| CVE-2024-54280 | CRITICAL | 9.8 | 0.6% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBo... |
| CVE-2024-54229 | CRITICAL | 9.8 | 0.4% | Dec 16, 2024 | Incorrect Privilege Assignment vulnerability in straightvisions GmbH SV100 Companion sv100-companion allows Privilege Es... |
| CVE-2024-43234 | CRITICAL | 9.8 | 0.6% | Dec 16, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authenticatio... |
| CVE-2024-56012 | CRITICAL | 9.8 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Flash News / Post (Responsive) flashnews-fading-effect-pearlb... |
| CVE-2024-55988 | CRITICAL | 9.3 | 1.1% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman... |
| CVE-2024-55982 | CRITICAL | 9.3 | 1.7% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share But... |
| CVE-2024-55981 | CRITICAL | 9.3 | 1.0% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nabajit Roy Nabz I... |
| CVE-2024-55980 | CRITICAL | 9.3 | 0.7% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robindkumar Wr Age... |
| CVE-2024-55978 | CRITICAL | 9.3 | 0.7% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WalletStation Code... |
| CVE-2024-55977 | CRITICAL | 9.3 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BinaryCarpenter La... |
| CVE-2024-55976 | CRITICAL | 9.3 | 1.1% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mikeleembruggen Cr... |
| CVE-2024-55972 | CRITICAL | 9.3 | 1.2% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chriscarvache eTem... |
| CVE-2024-54372 | CRITICAL | 9.6 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Insertify insertify allows Code Injection.This issue affe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now