2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52544 | CRITICAL | 9.8 | 1.1% | Dec 3, 2024 | An unauthenticated attacker can trigger a stack based buffer overflow in the DP Service (TCP port 3500). This vulnerabil... |
| CVE-2024-45676 | MEDIUM | 4.3 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insuf... |
| CVE-2024-41777 | HIGH | 7.5 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic k... |
| CVE-2024-41776 | MEDIUM | 6.5 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an att... |
| CVE-2024-41775 | HIGH | 7.5 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker ... |
| CVE-2024-25020 | CRITICAL | 9.8 | 0.3% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted fi... |
| CVE-2024-53867 | MEDIUM | 4.3 | 0.4% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0... |
| CVE-2024-53863 | CRITICAL | 9.1 | 0.6% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option ... |
| CVE-2024-52815 | MEDIUM | 5.3 | 0.5% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received ... |
| CVE-2024-52805 | HIGH | 7.5 | 0.7% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain conf... |
| CVE-2024-40691 | CRITICAL | 9.8 | 0.4% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of ... |
| CVE-2024-37303 | MEDIUM | 5.3 | 0.4% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote part... |
| CVE-2024-37302 | HIGH | 7.5 | 0.6% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where a... |
| CVE-2024-29404 | HIGH | 7.8 | 0.5% | Dec 3, 2024 | An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary co... |
| CVE-2024-25036 | LOW | 3.3 | 0.2% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security all... |
| CVE-2024-25035 | MEDIUM | 5.3 | 0.3% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of... |
| CVE-2024-25019 | CRITICAL | 9.8 | 0.3% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of fil... |
| CVE-2024-54000 | HIGH | 7.5 | 0.4% | Dec 3, 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor... |
| CVE-2024-53999 | MEDIUM | 5.4 | 0.5% | Dec 3, 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor... |
| CVE-2024-53257 | MEDIUM | 4.9 | 0.4% | Dec 3, 2024 | Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vt... |
| CVE-2024-12101 | — | — | — | Dec 3, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-11391 | HIGH | 7.5 | 0.7% | Dec 3, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2024-11200 | MEDIUM | 6.1 | 0.3% | Dec 3, 2024 | The Goodlayers Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘font-family’ parameter... |
| CVE-2024-9978 | MEDIUM | 5.5 | 0.1% | Dec 3, 2024 | in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
| CVE-2024-42422 | HIGH | 7.5 | 0.3% | Dec 3, 2024 | Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unaut... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now