2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12928 | HIGH | 8.8 | 0.4% | Dec 26, 2024 | A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. This affects an un... |
| CVE-2024-12926 | HIGH | 8.8 | 0.5% | Dec 25, 2024 | A vulnerability classified as critical was found in Codezips Project Management System 1.0. Affected by this vulnerabili... |
| CVE-2024-53291 | HIGH | 7.5 | 0.3% | Dec 25, 2024 | Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An ... |
| CVE-2024-52535 | HIGH | 8.8 | 0.5% | Dec 25, 2024 | Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prio... |
| CVE-2024-47978 | HIGH | 7.8 | 0.2% | Dec 25, 2024 | Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged... |
| CVE-2024-12428 | HIGH | 7.5 | 0.5% | Dec 25, 2024 | The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via t... |
| CVE-2024-1609 | HIGH | 8.7 | 0.5% | Dec 25, 2024 | In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation. |
| CVE-2024-12272 | HIGH | 8.8 | 0.7% | Dec 25, 2024 | The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPr... |
| CVE-2024-12746 | HIGH | 8.6 | 0.4% | Dec 24, 2024 | A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privilege... |
| CVE-2024-12745 | HIGH | 8.6 | 0.5% | Dec 24, 2024 | A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_sc... |
| CVE-2024-12744 | HIGH | 8.6 | 0.6% | Dec 24, 2024 | A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSc... |
| CVE-2024-53162 | HIGH | 7.1 | 0.3% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_4xxx - fix off by one in uof_get_na... |
| CVE-2024-53156 | HIGH | 7.8 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: add range check for conn_rsp_epid in h... |
| CVE-2024-53155 | HIGH | 7.1 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_i... |
| CVE-2024-53150 | HIGH | 7.1 | 1.3% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when findi... |
| CVE-2024-53147 | HIGH | 7.1 | 0.2% | Dec 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entrie... |
| CVE-2024-12881 | HIGH | 8.8 | 0.4% | Dec 24, 2024 | The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary ... |
| CVE-2024-12594 | HIGH | 8.8 | 0.7% | Dec 24, 2024 | The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Tempora... |
| CVE-2024-47515 | HIGH | 8.1 | 0.5% | Dec 24, 2024 | A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the di... |
| CVE-2024-12582 | HIGH | 7.1 | 0.5% | Dec 24, 2024 | A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metri... |
| CVE-2024-53961 | HIGH | 8.1 | 13.4% | Dec 23, 2024 | ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Di... |
| CVE-2024-56363 | HIGH | 7.8 | 0.3% | Dec 23, 2024 | APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed fo... |
| CVE-2024-56326 | HIGH | 7.8 | 0.5% | Dec 23, 2024 | Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects ca... |
| CVE-2024-56201 | HIGH | 8.8 | 0.3% | Dec 23, 2024 | Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allo... |
| CVE-2024-55947 | HIGH | 8.8 | 75.2% | Dec 23, 2024 | Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the ser... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now