2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42451 | MEDIUM | 6.5 | 0.3% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. Th... |
| CVE-2024-42449 | HIGH | 7.1 | 5.4% | Dec 4, 2024 | From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos... |
| CVE-2024-40717 | HIGH | 8.8 | 0.7% | Dec 4, 2024 | A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code exe... |
| CVE-2024-11985 | MEDIUM | 4.4 | 0.3% | Dec 4, 2024 | An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2... |
| CVE-2024-11479 | MEDIUM | 5.1 | 0.4% | Dec 4, 2024 | A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user... |
| CVE-2024-46624 | HIGH | 8.8 | 0.4% | Dec 3, 2024 | An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via ... |
| CVE-2024-53502 | LOW | 3.8 | 0.3% | Dec 3, 2024 | Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page. |
| CVE-2024-51363 | CRITICAL | 9.8 | 0.6% | Dec 3, 2024 | Insecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code. |
| CVE-2024-46625 | HIGH | 8.8 | 0.5% | Dec 3, 2024 | An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.... |
| CVE-2024-40391 | — | — | — | Dec 3, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-54131 | HIGH | 7.3 | 0.2% | Dec 3, 2024 | The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug ... |
| CVE-2024-53672 | MEDIUM | 6.3 | 0.4% | Dec 3, 2024 | A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run ... |
| CVE-2024-51773 | MEDIUM | 5.4 | 0.3% | Dec 3, 2024 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe... |
| CVE-2024-51772 | HIGH | 8 | 0.4% | Dec 3, 2024 | An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenti... |
| CVE-2024-45757 | HIGH | 7.2 | 0.4% | Dec 3, 2024 | An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-set... |
| CVE-2024-51771 | HIGH | 8.8 | 0.7% | Dec 3, 2024 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authe... |
| CVE-2024-51114 | HIGH | 8.8 | 0.8% | Dec 3, 2024 | An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute ar... |
| CVE-2024-53921 | LOW | 2.8 | 0.2% | Dec 3, 2024 | An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders ... |
| CVE-2024-50948 | HIGH | 7.5 | 0.6% | Dec 3, 2024 | mochiMQTT v2.6.3 is vulnerable to Denial of Service (DoS) due to improper resource management. An attacker can exhaust s... |
| CVE-2024-48080 | HIGH | 7.5 | 0.7% | Dec 3, 2024 | An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier i... |
| CVE-2024-12053 | HIGH | 8.8 | 0.8% | Dec 3, 2024 | Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object co... |
| CVE-2024-52548 | MEDIUM | 6.7 | 0.2% | Dec 3, 2024 | An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, an... |
| CVE-2024-52547 | HIGH | 7.2 | 0.7% | Dec 3, 2024 | An authenticated attacker can trigger a stack based buffer overflow in the DHIP Service (TCP port 80). This vulnerabilit... |
| CVE-2024-52546 | MEDIUM | 5.3 | 0.8% | Dec 3, 2024 | An unauthenticated attacker can perform a null pointer dereference in the DHIP Service (UDP port 37810). This vulnerabil... |
| CVE-2024-52545 | MEDIUM | 6.5 | 0.7% | Dec 3, 2024 | An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now