2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38488 | CRITICAL | 9.8 | 0.3% | Dec 13, 2024 | Dell RecoverPoint for Virtual Machines 6.0.x contains a vulnerability. An improper Restriction of Excessive Authenticati... |
| CVE-2024-11986 | CRITICAL | 9.6 | 0.6% | Dec 13, 2024 | Improper input handling in the 'Host Header' allows an unauthenticated attacker to store a payload in web application lo... |
| CVE-2024-21577 | CRITICAL | 10 | 0.6% | Dec 13, 2024 | ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint func... |
| CVE-2024-21576 | CRITICAL | 10 | 0.5% | Dec 13, 2024 | ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAd... |
| CVE-2024-52061 | CRITICAL | 9.8 | 0.4% | Dec 13, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core L... |
| CVE-2024-9290 | CRITICAL | 9.8 | 3.5% | Dec 13, 2024 | The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to mis... |
| CVE-2024-52057 | CRITICAL | 9.8 | 0.4% | Dec 13, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTI Connext Profes... |
| CVE-2024-11838 | CRITICAL | 9.8 | 0.4% | Dec 13, 2024 | External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion through use of an undocument... |
| CVE-2024-11837 | CRITICAL | 9.8 | 0.5% | Dec 13, 2024 | Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac allows... |
| CVE-2024-11834 | CRITICAL | 9.1 | 0.5% | Dec 13, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrar... |
| CVE-2024-11833 | CRITICAL | 9.1 | 0.5% | Dec 13, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PlexTrac allows arbitrar... |
| CVE-2024-12603 | CRITICAL | 9.8 | 0.5% | Dec 13, 2024 | A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application passwo... |
| CVE-2024-55875 | CRITICAL | 9.8 | 1.9% | Dec 12, 2024 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML Ex... |
| CVE-2024-55663 | CRITICAL | 9.8 | 0.7% | Dec 12, 2024 | XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc... |
| CVE-2024-54811 | CRITICAL | 9.8 | 0.6% | Dec 12, 2024 | A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to ex... |
| CVE-2024-49147 | CRITICAL | 9.8 | 1.3% | Dec 12, 2024 | Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on t... |
| CVE-2024-54810 | CRITICAL | 9.8 | 1.0% | Dec 12, 2024 | A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment Sy... |
| CVE-2024-55099 | CRITICAL | 9.8 | 1.0% | Dec 12, 2024 | A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows ... |
| CVE-2024-54842 | CRITICAL | 9.8 | 0.5% | Dec 12, 2024 | A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php vi... |
| CVE-2024-21575 | CRITICAL | 9.2 | 1.0% | Dec 12, 2024 | ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` fie... |
| CVE-2024-21574 | CRITICAL | 10 | 1.1% | Dec 12, 2024 | The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint us... |
| CVE-2024-10124 | CRITICAL | 9.8 | 31.2% | Dec 12, 2024 | The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitr... |
| CVE-2024-11015 | CRITICAL | 9.8 | 0.8% | Dec 12, 2024 | The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including... |
| CVE-2024-55660 | CRITICAL | 9.8 | 0.6% | Dec 12, 2024 | SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint... |
| CVE-2024-54534 | CRITICAL | 9.8 | 1.0% | Dec 12, 2024 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now