2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11398 | HIGH | 8.1 | 0.6% | Dec 4, 2024 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality ... |
| CVE-2024-54664 | — | — | — | Dec 4, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-52945. Reason: This candidate is a reservation d... |
| CVE-2024-54661 | CRITICAL | 9.8 | 0.8% | Dec 4, 2024 | readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file. |
| CVE-2024-9404 | HIGH | 8.7 | 0.7% | Dec 4, 2024 | This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of ... |
| CVE-2024-12123 | MEDIUM | 5.3 | 0.4% | Dec 4, 2024 | A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authent... |
| CVE-2024-12099 | MEDIUM | 4.3 | 0.3% | Dec 4, 2024 | The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in a... |
| CVE-2024-10885 | MEDIUM | 5.4 | 0.3% | Dec 4, 2024 | The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's... |
| CVE-2024-11897 | MEDIUM | 5.4 | 0.3% | Dec 4, 2024 | The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-11813 | MEDIUM | 6.1 | 0.2% | Dec 4, 2024 | The Pulsating Chat Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2024-11807 | MEDIUM | 6.1 | 0.3% | Dec 4, 2024 | The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' paramet... |
| CVE-2024-11747 | MEDIUM | 6.4 | 0.3% | Dec 4, 2024 | The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortc... |
| CVE-2024-11093 | MEDIUM | 5.5 | 0.2% | Dec 4, 2024 | The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due ... |
| CVE-2024-10952 | HIGH | 7.3 | 0.6% | Dec 4, 2024 | The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJ... |
| CVE-2024-10832 | MEDIUM | 6.1 | 0.4% | Dec 4, 2024 | The Posti Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the account_number and secre... |
| CVE-2024-10663 | MEDIUM | 4.3 | 0.2% | Dec 4, 2024 | The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-10587 | HIGH | 8.8 | 0.6% | Dec 4, 2024 | The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress... |
| CVE-2024-45207 | HIGH | 7 | 0.2% | Dec 4, 2024 | DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the a... |
| CVE-2024-45206 | MEDIUM | 6.5 | 0.2% | Dec 4, 2024 | A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests t... |
| CVE-2024-45205 | HIGH | 7.1 | 0.1% | Dec 4, 2024 | An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Networ... |
| CVE-2024-45204 | MEDIUM | 4.3 | 0.4% | Dec 4, 2024 | A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak N... |
| CVE-2024-42457 | MEDIUM | 6.5 | 0.4% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by le... |
| CVE-2024-42456 | HIGH | 8.8 | 0.4% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a me... |
| CVE-2024-42455 | HIGH | 8.1 | 14.0% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit i... |
| CVE-2024-42453 | HIGH | 8.1 | 0.3% | Dec 4, 2024 | A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected... |
| CVE-2024-42452 | HIGH | 8.8 | 0.5% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now