2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9672 | MEDIUM | 5.4 | 0.2% | Dec 10, 2024 | A reflected cross-site scripting (XSS) vulnerability exists in PaperCut NG/MF. This issue can be used to execute special... |
| CVE-2024-55638 | CRITICAL | 9.8 | 1.0% | Dec 10, 2024 | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f... |
| CVE-2024-55637 | CRITICAL | 9.8 | 0.8% | Dec 10, 2024 | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f... |
| CVE-2024-55636 | CRITICAL | 9.8 | 0.9% | Dec 10, 2024 | Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: f... |
| CVE-2024-55635 | MEDIUM | 6.1 | 0.3% | Dec 10, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core... |
| CVE-2024-55634 | HIGH | 8.1 | 0.4% | Dec 10, 2024 | A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fr... |
| CVE-2024-12393 | MEDIUM | 5.4 | 0.3% | Dec 10, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core... |
| CVE-2024-55601 | MEDIUM | 5.3 | 0.6% | Dec 9, 2024 | Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markd... |
| CVE-2024-50628 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local ar... |
| CVE-2024-50627 | HIGH | 8.8 | 0.3% | Dec 9, 2024 | An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file u... |
| CVE-2024-50626 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This... |
| CVE-2024-50625 | HIGH | 8 | 0.3% | Dec 9, 2024 | An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web appl... |
| CVE-2024-12174 | LOW | 2.7 | 0.2% | Dec 9, 2024 | An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged at... |
| CVE-2024-54151 | HIGH | 7.5 | 0.6% | Dec 9, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to... |
| CVE-2024-54149 | HIGH | 8.4 | 0.4% | Dec 9, 2024 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to ve... |
| CVE-2024-46455 | CRITICAL | 9.8 | 0.5% | Dec 9, 2024 | unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser. |
| CVE-2024-12369 | MEDIUM | 4.2 | 0.2% | Dec 9, 2024 | A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc... |
| CVE-2024-53441 | CRITICAL | 9.1 | 0.3% | Dec 9, 2024 | An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping at... |
| CVE-2024-54938 | HIGH | 7.5 | 0.5% | Dec 9, 2024 | A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to acc... |
| CVE-2024-54934 | CRITICAL | 9.8 | 0.5% | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php. |
| CVE-2024-54932 | CRITICAL | 9.8 | 0.5% | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php. |
| CVE-2024-54931 | CRITICAL | 9.8 | 0.6% | Dec 9, 2024 | A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote... |
| CVE-2024-54928 | HIGH | 7.2 | 0.5% | Dec 9, 2024 | kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php, |
| CVE-2024-54927 | HIGH | 7.2 | 0.5% | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php. |
| CVE-2024-54925 | CRITICAL | 9.8 | 0.6% | Dec 9, 2024 | A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remot... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now