2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51551 | CRITICAL | 10 | 0.4% | Dec 5, 2024 | Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default cred... |
| CVE-2024-51550 | CRITICAL | 9.8 | 1.8% | Dec 5, 2024 | Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in ... |
| CVE-2024-51549 | CRITICAL | 9.4 | 0.5% | Dec 5, 2024 | Absolute File Traversal vulnerabilities allows access and modification of un-intended resources. Affected products: ... |
| CVE-2024-51548 | HIGH | 8.8 | 0.6% | Dec 5, 2024 | Dangerous File Upload vulnerabilities allow upload of malicious scripts. Affected products: ABB ASPECT - Enterprise v... |
| CVE-2024-51546 | HIGH | 7.5 | 1.5% | Dec 5, 2024 | Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPEC... |
| CVE-2024-51545 | CRITICAL | 9.8 | 0.4% | Dec 5, 2024 | Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions. ... |
| CVE-2024-51544 | HIGH | 8.2 | 13.5% | Dec 5, 2024 | Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected produc... |
| CVE-2024-51543 | HIGH | 7.5 | 0.3% | Dec 5, 2024 | Information Disclosure vulnerabilities allow access to application configuration information. Affected products: ABB ... |
| CVE-2024-51542 | HIGH | 8.2 | 0.3% | Dec 5, 2024 | Configuration Download vulnerabilities allow access to dependency configuration information. Affected products: ABB A... |
| CVE-2024-51541 | HIGH | 7.5 | 0.3% | Dec 5, 2024 | Local File Inclusion vulnerabilities allow access to sensitive system information. Affected products: ABB ASPECT - En... |
| CVE-2024-48847 | CRITICAL | 9.1 | 0.3% | Dec 5, 2024 | MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or... |
| CVE-2024-48846 | HIGH | 7.3 | 0.6% | Dec 5, 2024 | Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or chan... |
| CVE-2024-48845 | CRITICAL | 9.8 | 1.8% | Dec 5, 2024 | Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that cou... |
| CVE-2024-48844 | MEDIUM | 6.5 | 0.9% | Dec 5, 2024 | Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products:... |
| CVE-2024-48843 | HIGH | 7.5 | 0.3% | Dec 5, 2024 | Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products:... |
| CVE-2024-48840 | CRITICAL | 9.8 | 2.1% | Dec 5, 2024 | Unauthorized Access vulnerabilities allow Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02;... |
| CVE-2024-48839 | CRITICAL | 9.8 | 2.8% | Dec 5, 2024 | Improper Input Validation vulnerability allows Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.0... |
| CVE-2024-12094 | MEDIUM | 5.4 | 0.1% | Dec 5, 2024 | This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the devic... |
| CVE-2024-11317 | CRITICAL | 10 | 0.4% | Dec 5, 2024 | Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportuni... |
| CVE-2024-11316 | HIGH | 7.5 | 0.6% | Dec 5, 2024 | Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product. Affected produc... |
| CVE-2024-52270 | HIGH | 8.2 | 0.2% | Dec 5, 2024 | User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Sp... |
| CVE-2024-52564 | HIGH | 7.5 | 0.6% | Dec 5, 2024 | Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX f... |
| CVE-2024-47133 | HIGH | 7.2 | 0.9% | Dec 5, 2024 | UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker... |
| CVE-2024-45841 | MEDIUM | 6.5 | 0.5% | Dec 5, 2024 | Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/E... |
| CVE-2024-11779 | MEDIUM | 6.4 | 0.3% | Dec 5, 2024 | The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocaro... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now