2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54154 | CRITICAL | 9.8 | 0.7% | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox |
| CVE-2024-10576 | CRITICAL | 9.4 | 0.2% | Dec 4, 2024 | Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast rece... |
| CVE-2024-52275 | CRITICAL | 9.8 | 0.6% | Dec 4, 2024 | Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromWizardHandle modules) allows ... |
| CVE-2024-52274 | CRITICAL | 9.8 | 0.4% | Dec 4, 2024 | Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoubleL2tpConfig->guest_ip_che... |
| CVE-2024-52273 | CRITICAL | 9.8 | 0.4% | Dec 4, 2024 | Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoublePppoeConfig->guest_ip_ch... |
| CVE-2024-52272 | CRITICAL | 9.8 | 0.4% | Dec 4, 2024 | Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromAdvSetLanip(overflow arg:lanM... |
| CVE-2024-54661 | CRITICAL | 9.8 | 0.8% | Dec 4, 2024 | readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file. |
| CVE-2024-51363 | CRITICAL | 9.8 | 0.6% | Dec 3, 2024 | Insecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code. |
| CVE-2024-52544 | CRITICAL | 9.8 | 1.1% | Dec 3, 2024 | An unauthenticated attacker can trigger a stack based buffer overflow in the DP Service (TCP port 3500). This vulnerabil... |
| CVE-2024-25020 | CRITICAL | 9.8 | 0.3% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted fi... |
| CVE-2024-53863 | CRITICAL | 9.1 | 0.6% | Dec 3, 2024 | Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option ... |
| CVE-2024-40691 | CRITICAL | 9.8 | 0.4% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of ... |
| CVE-2024-25019 | CRITICAL | 9.8 | 0.3% | Dec 3, 2024 | IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of fil... |
| CVE-2024-49415 | CRITICAL | 9.8 | 1.0% | Dec 3, 2024 | Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code. |
| CVE-2024-53477 | CRITICAL | 9.8 | 0.8% | Dec 2, 2024 | JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.ja... |
| CVE-2024-53900 | CRITICAL | 9.1 | 3.9% | Dec 2, 2024 | Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. |
| CVE-2024-52724 | CRITICAL | 9.8 | 0.6% | Dec 2, 2024 | ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php. |
| CVE-2024-53990 | CRITICAL | 9.2 | 0.6% | Dec 2, 2024 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2024-52732 | CRITICAL | 9.1 | 0.4% | Dec 2, 2024 | Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system bei... |
| CVE-2024-46909 | CRITICAL | 9.8 | 49.2% | Dec 2, 2024 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability t... |
| CVE-2024-10905 | CRITICAL | 9.8 | 0.9% | Dec 2, 2024 | IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, Identity... |
| CVE-2024-52476 | CRITICAL | 10 | 0.5% | Dec 2, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows... |
| CVE-2024-12007 | CRITICAL | 9.8 | 0.5% | Dec 1, 2024 | A vulnerability, which was classified as critical, was found in code-projects Farmacia 1.0. This affects an unknown part... |
| CVE-2024-53739 | CRITICAL | 9.8 | 0.6% | Nov 30, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-53507 | CRITICAL | 9.8 | 0.6% | Nov 29, 2024 | A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now