2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12483 | MEDIUM | 5.9 | 3.4% | Dec 12, 2024 | A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of t... |
| CVE-2024-12482 | MEDIUM | 4.3 | 0.9% | Dec 12, 2024 | A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is th... |
| CVE-2024-12481 | HIGH | 8.8 | 0.6% | Dec 12, 2024 | A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been declared as critical. Affected by this vulnerabili... |
| CVE-2024-12480 | HIGH | 8.8 | 0.5% | Dec 12, 2024 | A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been classified as critical. Affected is the function s... |
| CVE-2024-12479 | HIGH | 8.8 | 0.6% | Dec 12, 2024 | A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2 and classified as critical. This issue affects the function sea... |
| CVE-2024-12382 | HIGH | 8.8 | 4.1% | Dec 12, 2024 | Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit he... |
| CVE-2024-12381 | HIGH | 8.8 | 4.0% | Dec 12, 2024 | Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2024-11950 | HIGH | 8.8 | 0.5% | Dec 12, 2024 | XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2024-11949 | HIGH | 8.8 | 0.8% | Dec 12, 2024 | GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2024-11948 | CRITICAL | 9.8 | 1.4% | Dec 12, 2024 | GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a... |
| CVE-2024-11947 | HIGH | 8.8 | 0.8% | Dec 12, 2024 | GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2024-11872 | HIGH | 7.8 | 0.2% | Dec 12, 2024 | Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows lo... |
| CVE-2024-9845 | HIGH | 7.8 | 0.2% | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authent... |
| CVE-2024-8496 | HIGH | 7.8 | 0.2% | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local ... |
| CVE-2024-48912 | HIGH | 8.1 | 0.4% | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an aut... |
| CVE-2024-47761 | HIGH | 7.2 | 0.5% | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an admin... |
| CVE-2024-47760 | HIGH | 8.8 | 0.5% | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a techn... |
| CVE-2024-11598 | HIGH | 7.8 | 0.2% | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, ... |
| CVE-2024-11597 | HIGH | 7.8 | 0.2% | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, ... |
| CVE-2024-10251 | HIGH | 7.8 | 0.2% | Dec 11, 2024 | Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local au... |
| CVE-2024-53677 | CRITICAL | 9.8 | 78.2% | Dec 11, 2024 | File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal an... |
| CVE-2024-47758 | HIGH | 8.8 | 0.4% | Dec 11, 2024 | GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an auth... |
| CVE-2024-28141 | MEDIUM | 6.3 | 0.3% | Dec 11, 2024 | The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users ... |
| CVE-2024-28140 | MEDIUM | 6.1 | 0.3% | Dec 11, 2024 | The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser... |
| CVE-2024-28139 | HIGH | 8.8 | 0.7% | Dec 11, 2024 | The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as r... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now