2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9651 | MEDIUM | 6.1 | 0.4% | Dec 9, 2024 | The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-12360 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as critical. T... |
| CVE-2024-12359 | MEDIUM | 5.4 | 0.4% | Dec 9, 2024 | A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability ... |
| CVE-2024-12358 | HIGH | 8.8 | 4.8% | Dec 9, 2024 | A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown par... |
| CVE-2024-12357 | MEDIUM | 5.3 | 0.4% | Dec 9, 2024 | A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affec... |
| CVE-2024-53285 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in DDNS Record functi... |
| CVE-2024-53284 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect Setti... |
| CVE-2024-53283 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Router Port Forwar... |
| CVE-2024-53282 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in WiFi Connect MAC F... |
| CVE-2024-53281 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Network WOL functi... |
| CVE-2024-53280 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in network center pol... |
| CVE-2024-53279 | MEDIUM | 5.9 | 0.3% | Dec 9, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station funct... |
| CVE-2024-55582 | MEDIUM | 5.7 | 0.1% | Dec 9, 2024 | Oxide before 6 has unencrypted Control Plane datastores. |
| CVE-2024-55580 | HIGH | 7.5 | 0.3% | Dec 9, 2024 | An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network ac... |
| CVE-2024-55579 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network ... |
| CVE-2024-55578 | MEDIUM | 4.3 | 0.3% | Dec 9, 2024 | Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log f... |
| CVE-2024-55566 | MEDIUM | 6.6 | 0.2% | Dec 9, 2024 | ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded... |
| CVE-2024-55565 | MEDIUM | 4.3 | 0.7% | Dec 9, 2024 | nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version. |
| CVE-2024-55564 | CRITICAL | 9.8 | 0.5% | Dec 9, 2024 | The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow. |
| CVE-2024-12355 | HIGH | 7.8 | 0.3% | Dec 9, 2024 | A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affecte... |
| CVE-2024-12354 | HIGH | 7.8 | 0.4% | Dec 9, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0. Affecte... |
| CVE-2024-12353 | HIGH | 7.8 | 0.3% | Dec 9, 2024 | A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0.... |
| CVE-2024-12352 | CRITICAL | 9.8 | 0.7% | Dec 9, 2024 | A vulnerability classified as problematic was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affec... |
| CVE-2024-55563 | MEDIUM | 5.3 | 0.6% | Dec 9, 2024 | Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024... |
| CVE-2024-12351 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now