2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11950 | HIGH | 8.8 | 0.5% | Dec 12, 2024 | XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2024-11949 | HIGH | 8.8 | 0.8% | Dec 12, 2024 | GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2024-11948 | CRITICAL | 9.8 | 1.4% | Dec 12, 2024 | GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a... |
| CVE-2024-11947 | HIGH | 8.8 | 0.8% | Dec 12, 2024 | GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2024-11872 | HIGH | 7.8 | 0.2% | Dec 12, 2024 | Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows lo... |
| CVE-2024-9845 | HIGH | 7.8 | 0.2% | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authent... |
| CVE-2024-8496 | HIGH | 7.8 | 0.2% | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local ... |
| CVE-2024-48912 | HIGH | 8.1 | 0.4% | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an aut... |
| CVE-2024-47761 | HIGH | 7.2 | 0.5% | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an admin... |
| CVE-2024-47760 | HIGH | 8.8 | 0.5% | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a techn... |
| CVE-2024-11598 | HIGH | 7.8 | 0.2% | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, ... |
| CVE-2024-11597 | HIGH | 7.8 | 0.2% | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, ... |
| CVE-2024-10251 | HIGH | 7.8 | 0.2% | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local au... |
| CVE-2024-53677 | CRITICAL | 9.8 | 78.2% | Dec 11, 2024 | File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal an... |
| CVE-2024-47758 | HIGH | 8.8 | 0.4% | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an auth... |
| CVE-2024-28141 | MEDIUM | 6.3 | 0.3% | Dec 11, 2024 | The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users ... |
| CVE-2024-28140 | MEDIUM | 6.1 | 0.3% | Dec 11, 2024 | The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser... |
| CVE-2024-28139 | HIGH | 8.8 | 0.7% | Dec 11, 2024 | The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as r... |
| CVE-2024-50585 | MEDIUM | 4.7 | 0.5% | Dec 11, 2024 | Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary J... |
| CVE-2024-51460 | MEDIUM | 4.3 | 0.3% | Dec 11, 2024 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed... |
| CVE-2024-11351 | MEDIUM | 5.3 | 0.4% | Dec 11, 2024 | The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable t... |
| CVE-2024-12325 | MEDIUM | 6.1 | 0.3% | Dec 11, 2024 | The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all vers... |
| CVE-2024-12294 | MEDIUM | 5.3 | 0.4% | Dec 11, 2024 | The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions... |
| CVE-2024-11840 | HIGH | 7.1 | 0.4% | Dec 11, 2024 | The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and ... |
| CVE-2024-11008 | MEDIUM | 5.3 | 0.4% | Dec 11, 2024 | The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now