2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12350 | HIGH | 8.8 | 3.6% | Dec 9, 2024 | A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update... |
| CVE-2024-12349 | HIGH | 8.8 | 0.4% | Dec 9, 2024 | A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an un... |
| CVE-2024-12348 | MEDIUM | 6.1 | 0.4% | Dec 9, 2024 | A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is ... |
| CVE-2024-12347 | MEDIUM | 6.9 | 0.6% | Dec 9, 2024 | A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This ... |
| CVE-2024-12346 | MEDIUM | 5.3 | 0.4% | Dec 9, 2024 | A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unk... |
| CVE-2024-55560 | CRITICAL | 9.8 | 0.6% | Dec 8, 2024 | MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persi... |
| CVE-2024-12344 | CRITICAL | 9.8 | 1.8% | Dec 8, 2024 | A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unkno... |
| CVE-2024-12343 | HIGH | 8.8 | 4.7% | Dec 8, 2024 | A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown funct... |
| CVE-2024-12342 | HIGH | 7.1 | 8.9% | Dec 8, 2024 | A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. It has been rated as critical. This issue affects some u... |
| CVE-2024-12209 | CRITICAL | 9.8 | 15.0% | Dec 8, 2024 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all ve... |
| CVE-2024-53473 | HIGH | 7.5 | 0.6% | Dec 7, 2024 | WeGIA 3.2.0 before 3998672 does not verify permission to change a password. |
| CVE-2024-47107 | MEDIUM | 5.4 | 0.2% | Dec 7, 2024 | IBM QRadar SIEM 7.5 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed... |
| CVE-2024-41762 | MEDIUM | 6.5 | 0.4% | Dec 7, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv... |
| CVE-2024-47115 | HIGH | 7.8 | 0.2% | Dec 7, 2024 | IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improp... |
| CVE-2024-37071 | MEDIUM | 6.5 | 0.4% | Dec 7, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user... |
| CVE-2024-11501 | HIGH | 8.8 | 0.6% | Dec 7, 2024 | The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via des... |
| CVE-2024-11464 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in ... |
| CVE-2024-11457 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The Feedpress Generator – External RSS Frontend Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Sc... |
| CVE-2024-11380 | MEDIUM | 6.4 | 0.2% | Dec 7, 2024 | The Mini Program API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'qvideo' shortco... |
| CVE-2024-12270 | HIGH | 7.5 | 3.5% | Dec 7, 2024 | The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter ... |
| CVE-2024-12253 | MEDIUM | 5.4 | 0.3% | Dec 7, 2024 | The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2024-12128 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected ... |
| CVE-2024-11374 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The TWChat – Send or receive messages from users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du... |
| CVE-2024-11367 | MEDIUM | 6.1 | 0.3% | Dec 7, 2024 | The Smoove connector for Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the... |
| CVE-2024-11010 | HIGH | 7.2 | 0.8% | Dec 7, 2024 | The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local JavaScript File Inclu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now