2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53457 | MEDIUM | 5.4 | 42.5% | Dec 5, 2024 | A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows ... |
| CVE-2024-12064 | — | — | — | Dec 5, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-53523 | HIGH | 7.5 | 0.7% | Dec 5, 2024 | JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file functi... |
| CVE-2024-53589 | HIGH | 8.4 | 0.3% | Dec 5, 2024 | GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex forma... |
| CVE-2024-53442 | CRITICAL | 9.8 | 1.3% | Dec 5, 2024 | whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component. |
| CVE-2024-41579 | CRITICAL | 9.8 | 0.5% | Dec 5, 2024 | DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause ... |
| CVE-2024-11148 | HIGH | 8.7 | 0.4% | Dec 5, 2024 | In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when ha... |
| CVE-2024-10933 | MEDIUM | 5.5 | 0.3% | Dec 5, 2024 | In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid ... |
| CVE-2024-12235 | HIGH | 8.8 | 0.6% | Dec 5, 2024 | A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared a... |
| CVE-2024-12130 | HIGH | 7.8 | 0.3% | Dec 5, 2024 | An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threa... |
| CVE-2024-11158 | HIGH | 8.5 | 0.2% | Dec 5, 2024 | An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a... |
| CVE-2024-11156 | HIGH | 7.8 | 0.2% | Dec 5, 2024 | An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a th... |
| CVE-2024-11155 | HIGH | 8.5 | 0.2% | Dec 5, 2024 | A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat acto... |
| CVE-2024-54128 | MEDIUM | 4.6 | 0.3% | Dec 5, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a f... |
| CVE-2024-53846 | MEDIUM | 5.5 | 0.2% | Dec 5, 2024 | OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainl... |
| CVE-2024-53490 | HIGH | 7.5 | 0.7% | Dec 5, 2024 | Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java. |
| CVE-2024-12234 | CRITICAL | 9.8 | 0.8% | Dec 5, 2024 | A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Aff... |
| CVE-2024-12233 | CRITICAL | 9.8 | 0.8% | Dec 5, 2024 | A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects ... |
| CVE-2024-54130 | CRITICAL | 9.2 | 0.4% | Dec 5, 2024 | The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A se... |
| CVE-2024-54129 | CRITICAL | 9.2 | 0.4% | Dec 5, 2024 | The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vu... |
| CVE-2024-54001 | MEDIUM | 5.5 | 0.4% | Dec 5, 2024 | Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the... |
| CVE-2024-53857 | HIGH | 7.5 | 0.4% | Dec 5, 2024 | rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vul... |
| CVE-2024-53856 | HIGH | 7.5 | 0.4% | Dec 5, 2024 | rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by provi... |
| CVE-2024-53472 | HIGH | 8.8 | 0.3% | Dec 5, 2024 | WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF). |
| CVE-2024-53471 | MEDIUM | 6.1 | 0.3% | Dec 5, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now