2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45337 | CRITICAL | 9.1 | 3.1% | Dec 12, 2024 | Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback... |
| CVE-2024-42448 | CRITICAL | 9.9 | 20.1% | Dec 12, 2024 | From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos... |
| CVE-2024-12484 | CRITICAL | 9.8 | 0.9% | Dec 12, 2024 | A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects ... |
| CVE-2024-11948 | CRITICAL | 9.8 | 1.4% | Dec 12, 2024 | GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a... |
| CVE-2024-53677 | CRITICAL | 9.8 | 78.2% | Dec 11, 2024 | File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal an... |
| CVE-2024-11737 | CRITICAL | 9.8 | 0.6% | Dec 11, 2024 | CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidential... |
| CVE-2024-54036 | CRITICAL | 9.3 | 0.7% | Dec 10, 2024 | Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that c... |
| CVE-2024-54034 | CRITICAL | 9.3 | 0.7% | Dec 10, 2024 | Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If... |
| CVE-2024-54032 | CRITICAL | 9.3 | 0.8% | Dec 10, 2024 | Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that c... |
| CVE-2024-53480 | CRITICAL | 9.8 | 0.6% | Dec 10, 2024 | Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` par... |
| CVE-2024-46340 | CRITICAL | 9.8 | 0.3% | Dec 10, 2024 | TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user cr... |
| CVE-2024-46442 | CRITICAL | 9.8 | 0.6% | Dec 10, 2024 | An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attac... |
| CVE-2024-11639 | CRITICAL | 9.8 | 4.8% | Dec 10, 2024 | An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to... |
| CVE-2024-53866 | CRITICAL | 9.8 | 0.9% | Dec 10, 2024 | The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one works... |
| CVE-2024-12286 | CRITICAL | 9.8 | 0.4% | Dec 10, 2024 | MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials. |
| CVE-2024-55547 | CRITICAL | 9.8 | 16.9% | Dec 10, 2024 | SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e. |
| CVE-2024-45494 | CRITICAL | 9.8 | 0.5% | Dec 10, 2024 | An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an ... |
| CVE-2024-45493 | CRITICAL | 9.8 | 0.4% | Dec 10, 2024 | An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has int... |
| CVE-2024-54152 | CRITICAL | 9.3 | 2.3% | Dec 10, 2024 | Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3... |
| CVE-2024-54751 | CRITICAL | 9.8 | 0.4% | Dec 10, 2024 | COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows at... |
| CVE-2024-5660 | CRITICAL | 9.8 | 0.5% | Dec 10, 2024 | Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Co... |
| CVE-2024-55586 | CRITICAL | 9.8 | 0.5% | Dec 10, 2024 | Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly p... |
| CVE-2024-47484 | CRITICAL | 9.8 | 0.7% | Dec 10, 2024 | Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Impr... |
| CVE-2024-37143 | CRITICAL | 9.8 | 0.8% | Dec 10, 2024 | Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.... |
| CVE-2024-53552 | CRITICAL | 9.8 | 0.7% | Dec 10, 2024 | CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now