2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54747 | CRITICAL | 9.8 | 0.5% | Dec 6, 2024 | WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacke... |
| CVE-2024-54745 | CRITICAL | 9.8 | 0.5% | Dec 6, 2024 | WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows ... |
| CVE-2024-54137 | HIGH | 7.5 | 0.4% | Dec 6, 2024 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A co... |
| CVE-2024-54136 | CRITICAL | 9.8 | 0.7% | Dec 6, 2024 | ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnera... |
| CVE-2024-54135 | HIGH | 8.8 | 0.7% | Dec 6, 2024 | ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are v... |
| CVE-2024-50677 | MEDIUM | 6.1 | 0.5% | Dec 6, 2024 | A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or ... |
| CVE-2024-30129 | MEDIUM | 5.3 | 0.3% | Dec 6, 2024 | The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the ... |
| CVE-2024-12254 | HIGH | 8.7 | 1.9% | Dec 6, 2024 | Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signa... |
| CVE-2024-54141 | HIGH | 7.5 | 0.5% | Dec 6, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, p... |
| CVE-2024-42196 | MEDIUM | 5.5 | 0.1% | Dec 6, 2024 | HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP ... |
| CVE-2024-11738 | HIGH | 7.5 | 0.7% | Dec 6, 2024 | A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmente... |
| CVE-2024-54216 | HIGH | 7.7 | 0.5% | Dec 6, 2024 | Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForm... |
| CVE-2024-54214 | CRITICAL | 10 | 0.7% | Dec 6, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in roninwp Revy revy allows Upload a Web Shell to a Web Se... |
| CVE-2024-54213 | MEDIUM | 6.5 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zionbuilder ZionBu... |
| CVE-2024-54212 | MEDIUM | 5.4 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical ... |
| CVE-2024-54211 | MEDIUM | 5.4 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderl... |
| CVE-2024-54210 | MEDIUM | 6.5 | 0.2% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codexshaper Advanc... |
| CVE-2024-54209 | HIGH | 7.1 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Awesome ... |
| CVE-2024-54208 | HIGH | 7.1 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joni Halabi Block ... |
| CVE-2024-54207 | MEDIUM | 5.9 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Marka WordPress... |
| CVE-2024-54206 | MEDIUM | 5.9 | 0.3% | Dec 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in URBAN BASE Z-Downl... |
| CVE-2024-54205 | HIGH | 7.1 | 0.2% | Dec 6, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget postman-widget allows Cross Site Request Forgery... |
| CVE-2024-53826 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | Missing Authorization vulnerability in WPSight WPCasa wpcasa allows Accessing Functionality Not Properly Constrained by ... |
| CVE-2024-53825 | HIGH | 7.2 | 0.3% | Dec 6, 2024 | Missing Authorization vulnerability in Ninja Team Filebird filebird allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2024-53824 | HIGH | 7.5 | 0.6% | Dec 6, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now