2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46603 | HIGH | 7.5 | 0.7% | Jan 7, 2025 | An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows att... |
| CVE-2024-46602 | HIGH | 7.5 | 0.7% | Jan 7, 2025 | An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) v... |
| CVE-2024-46601 | HIGH | 7.5 | 0.6% | Jan 7, 2025 | Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow. |
| CVE-2024-46242 | HIGH | 7.5 | 0.7% | Jan 7, 2025 | An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a R... |
| CVE-2024-40702 | HIGH | 8.2 | 0.3% | Jan 7, 2025 | IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid t... |
| CVE-2024-52367 | HIGH | 7.5 | 0.3% | Jan 7, 2025 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could disclose sensitive system information to an unauthori... |
| CVE-2024-56300 | HIGH | 7.5 | 0.5% | Jan 7, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in wpspin Post/Page Copying Tool postpage-import-export-... |
| CVE-2024-56299 | HIGH | 7.1 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pektsekye Notify O... |
| CVE-2024-56296 | HIGH | 7.1 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kitae Park Mang Bo... |
| CVE-2024-56291 | HIGH | 8.1 | 0.4% | Jan 7, 2025 | Deserialization of Untrusted Data vulnerability in plainware PlainInventory z-inventory-manager allows Object Injection.... |
| CVE-2024-56289 | HIGH | 7.1 | 0.7% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groun... |
| CVE-2024-56286 | HIGH | 7.5 | 0.6% | Jan 7, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Classic A... |
| CVE-2024-56283 | HIGH | 8.1 | 0.4% | Jan 7, 2025 | Deserialization of Untrusted Data vulnerability in plainware Locatoraid Store Locator locatoraid allows Object Injection... |
| CVE-2024-56282 | HIGH | 7.5 | 0.6% | Jan 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-56281 | HIGH | 7.5 | 0.8% | Jan 7, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-56280 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | Incorrect Privilege Assignment vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Privilege Escalat... |
| CVE-2024-56276 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Co... |
| CVE-2024-51715 | HIGH | 8.5 | 0.4% | Jan 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWh... |
| CVE-2024-51700 | HIGH | 7.1 | 0.3% | Jan 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eutrue NAVER Analy... |
| CVE-2024-49644 | HIGH | 8.8 | 0.4% | Jan 7, 2025 | Incorrect Privilege Assignment vulnerability in AllAccessible Accessibility by AllAccessible allaccessible allows Privil... |
| CVE-2024-49249 | HIGH | 8.6 | 0.5% | Jan 7, 2025 | Path Traversal: '.../...//' vulnerability in SMSA Express SMSA Shipping smsa-shipping-official allows Path Traversal.Thi... |
| CVE-2024-12152 | HIGH | 7.5 | 1.0% | Jan 7, 2025 | The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin... |
| CVE-2024-47398 | HIGH | 8.8 | 0.2% | Jan 7, 2025 | in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the device is unable to boot up through out-of-bou... |
| CVE-2024-12202 | HIGH | 8.8 | 0.5% | Jan 7, 2025 | The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal... |
| CVE-2024-11627 | HIGH | 8.1 | 0.3% | Jan 7, 2025 | : Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Site... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now