2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54154 | CRITICAL | 9.8 | 0.7% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox |
| CVE-2024-54153 | MEDIUM | 6.5 | 0.4% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query par... |
| CVE-2024-52278 | — | — | — | Dec 4, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-52269 | HIGH | 8.2 | 0.3% | Dec 4, 2024 | User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The Saa... |
| CVE-2024-11854 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The Listdom – Business Directory and Classified Ads Listings WordPress Plugin plugin for WordPress is vulnerable to Stor... |
| CVE-2024-10576 | CRITICAL | 9.4 | 0.2% | Dec 4, 2024 | Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast rece... |
| CVE-2024-52277 | HIGH | 8.2 | 0.2% | Dec 4, 2024 | User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displaye... |
| CVE-2024-52276 | HIGH | 8.2 | 0.3% | Dec 4, 2024 | User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. 1. Disp... |
| CVE-2024-52275 | CRITICAL | 9.8 | 0.6% | Dec 4, 2024 | Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromWizardHandle modules) allows ... |
| CVE-2024-52274 | CRITICAL | 9.8 | 0.4% | Dec 4, 2024 | Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoubleL2tpConfig->guest_ip_che... |
| CVE-2024-52273 | CRITICAL | 9.8 | 0.4% | Dec 4, 2024 | Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoublePppoeConfig->guest_ip_ch... |
| CVE-2024-52272 | CRITICAL | 9.8 | 0.4% | Dec 4, 2024 | Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromAdvSetLanip(overflow arg:lanM... |
| CVE-2024-12107 | HIGH | 7.5 | 0.5% | Dec 4, 2024 | Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause... |
| CVE-2024-11814 | MEDIUM | 6.1 | 0.3% | Dec 4, 2024 | The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2024-5020 | MEDIUM | 6.4 | 0.4% | Dec 4, 2024 | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScrip... |
| CVE-2024-11952 | HIGH | 7.5 | 0.9% | Dec 4, 2024 | The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all... |
| CVE-2024-11880 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-10787 | MEDIUM | 4.3 | 0.3% | Dec 4, 2024 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to... |
| CVE-2024-10567 | HIGH | 7.5 | 0.4% | Dec 4, 2024 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2024-11903 | MEDIUM | 6.4 | 0.2% | Dec 4, 2024 | The WP eCards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ecard' shortcode in al... |
| CVE-2024-11769 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'f... |
| CVE-2024-11466 | MEDIUM | 6.1 | 0.3% | Dec 4, 2024 | The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't... |
| CVE-2024-11293 | HIGH | 8.1 | 0.5% | Dec 4, 2024 | The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & ... |
| CVE-2024-10664 | MEDIUM | 4.3 | 0.3% | Dec 4, 2024 | The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2024-45717 | MEDIUM | 4.8 | 0.4% | Dec 4, 2024 | The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now