2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53470 | MEDIUM | 6.1 | 0.4% | Dec 5, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA... |
| CVE-2024-12247 | MEDIUM | 4.3 | 0.2% | Dec 5, 2024 | Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updat... |
| CVE-2024-12232 | MEDIUM | 6.1 | 0.4% | Dec 5, 2024 | A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulner... |
| CVE-2024-12231 | CRITICAL | 9.8 | 0.7% | Dec 5, 2024 | A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an ... |
| CVE-2024-10716 | MEDIUM | 4.8 | 0.2% | Dec 5, 2024 | Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search. |
| CVE-2024-12230 | CRITICAL | 9.8 | 0.7% | Dec 5, 2024 | A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 1.0. Affecte... |
| CVE-2024-12229 | CRITICAL | 9.8 | 0.7% | Dec 5, 2024 | A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnera... |
| CVE-2024-11942 | MEDIUM | 5.9 | 0.4% | Dec 5, 2024 | A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10. |
| CVE-2024-11941 | HIGH | 7.5 | 0.4% | Dec 5, 2024 | A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, fr... |
| CVE-2024-54679 | MEDIUM | 6.5 | 0.9% | Dec 5, 2024 | CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions. |
| CVE-2024-53703 | HIGH | 8.1 | 12.7% | Dec 5, 2024 | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by... |
| CVE-2024-53702 | MEDIUM | 5.3 | 0.3% | Dec 5, 2024 | Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup ... |
| CVE-2024-52271 | HIGH | 8.2 | 0.2% | Dec 5, 2024 | User Interface (UI) Misrepresentation of Critical Information vulnerability in Documenso allows Content Spoofing.Display... |
| CVE-2024-45319 | MEDIUM | 6.3 | 0.2% | Dec 5, 2024 | A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authentica... |
| CVE-2024-45318 | HIGH | 8.1 | 1.0% | Dec 5, 2024 | A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buf... |
| CVE-2024-40763 | HIGH | 7.5 | 0.9% | Dec 5, 2024 | Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote aut... |
| CVE-2024-12228 | CRITICAL | 9.8 | 0.7% | Dec 5, 2024 | A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. Affected is an unkn... |
| CVE-2024-12227 | MEDIUM | 6.8 | 0.2% | Dec 5, 2024 | A vulnerability, which was classified as problematic, was found in MSI Dragon Center up to 2.0.146.0. This affects the f... |
| CVE-2024-6784 | CRITICAL | 9.9 | 0.5% | Dec 5, 2024 | Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and un... |
| CVE-2024-6516 | MEDIUM | 6.1 | 1.1% | Dec 5, 2024 | Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a clien... |
| CVE-2024-6515 | HIGH | 8.1 | 0.4% | Dec 5, 2024 | Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher p... |
| CVE-2024-54127 | MEDIUM | 4.3 | 0.1% | Dec 5, 2024 | This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without pro... |
| CVE-2024-54126 | HIGH | 8.5 | 0.1% | Dec 5, 2024 | This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upg... |
| CVE-2024-51555 | CRITICAL | 10 | 0.4% | Dec 5, 2024 | Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since ... |
| CVE-2024-51554 | CRITICAL | 9.8 | 0.4% | Dec 5, 2024 | Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default cred... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now