2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39890 | HIGH | 8.1 | 0.4% | Dec 2, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108... |
| CVE-2024-53900 | CRITICAL | 9.1 | 3.9% | Dec 2, 2024 | Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. |
| CVE-2024-39343 | HIGH | 7 | 0.4% | Dec 2, 2024 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 24... |
| CVE-2024-5890 | MEDIUM | 5.1 | 0.3% | Dec 2, 2024 | ServiceNow has addressed an HTML injection vulnerability that was identified in the Now Platform. This vulnerability cou... |
| CVE-2024-53617 | MEDIUM | 4.8 | 0.5% | Dec 2, 2024 | A Cross Site Scripting vulnerability in LibrePhotos before commit 32237 allows attackers to takeover any account via upl... |
| CVE-2024-53484 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard-coded JWT signing key. |
| CVE-2024-52724 | CRITICAL | 9.8 | 0.6% | Dec 2, 2024 | ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php. |
| CVE-2024-53990 | CRITICAL | 9.2 | 0.6% | Dec 2, 2024 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2024-53566 | MEDIUM | 5.5 | 0.3% | Dec 2, 2024 | An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows... |
| CVE-2024-53564 | HIGH | 7.2 | 0.3% | Dec 2, 2024 | A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) fil... |
| CVE-2024-53992 | HIGH | 8.8 | 0.4% | Dec 2, 2024 | unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malic... |
| CVE-2024-53364 | MEDIUM | 5.4 | 0.3% | Dec 2, 2024 | A SQL injection vulnerability was found in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/view-detail.php.... |
| CVE-2024-53259 | MEDIUM | 6.5 | 0.6% | Dec 2, 2024 | quic-go is an implementation of the QUIC protocol in Go. An off-path attacker can inject an ICMP Packet Too Large packet... |
| CVE-2024-52806 | HIGH | 8.3 | 0.4% | Dec 2, 2024 | SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, ... |
| CVE-2024-52596 | HIGH | 8.8 | 1.0% | Dec 2, 2024 | SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for ... |
| CVE-2024-50381 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim ... |
| CVE-2024-50380 | HIGH | 8.7 | 0.5% | Dec 2, 2024 | Snap One OVRC cloud uses the MAC address as an identifier to provide information when requested. An attacker can imperso... |
| CVE-2024-49763 | HIGH | 8.7 | 0.5% | Dec 2, 2024 | PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensiti... |
| CVE-2024-53984 | MEDIUM | 4.3 | 0.4% | Dec 2, 2024 | Nanopb is a small code-size Protocol Buffers implementation. When the compile time option PB_ENABLE_MALLOC is enabled, ... |
| CVE-2024-53981 | HIGH | 7.5 | 0.6% | Dec 2, 2024 | python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks ... |
| CVE-2024-53862 | HIGH | 7.5 | 0.6% | Dec 2, 2024 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. When us... |
| CVE-2024-53459 | MEDIUM | 5.4 | 0.3% | Dec 2, 2024 | Sysax Multi Server 6.99 is vulnerable to Cross Site Scripting (XSS) via the /scgi?sid parameter. |
| CVE-2024-8785 | MEDIUM | 5.3 | 9.5% | Dec 2, 2024 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create ... |
| CVE-2024-52732 | CRITICAL | 9.1 | 0.4% | Dec 2, 2024 | Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system bei... |
| CVE-2024-46909 | CRITICAL | 9.8 | 49.2% | Dec 2, 2024 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now