2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53256 | HIGH | 7.8 | 1.2% | Dec 23, 2024 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code ... |
| CVE-2024-45387 | HIGH | 8.8 | 41.8% | Dec 23, 2024 | An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with... |
| CVE-2024-12903 | HIGH | 7.8 | 0.2% | Dec 23, 2024 | Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could expl... |
| CVE-2024-12902 | HIGH | 8.4 | 0.2% | Dec 23, 2024 | ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows... |
| CVE-2024-54082 | HIGH | 7.2 | 1.2% | Dec 23, 2024 | home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore functio... |
| CVE-2024-45721 | HIGH | 7.2 | 1.2% | Dec 23, 2024 | home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST n... |
| CVE-2024-56375 | HIGH | 7.5 | 0.4% | Dec 22, 2024 | An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from... |
| CVE-2024-56311 | HIGH | 8.8 | 0.3% | Dec 22, 2024 | REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Reques... |
| CVE-2024-56310 | HIGH | 8.8 | 0.2% | Dec 22, 2024 | REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery... |
| CVE-2024-12891 | HIGH | 8.8 | 0.5% | Dec 22, 2024 | A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an ... |
| CVE-2024-12890 | HIGH | 8.8 | 0.5% | Dec 22, 2024 | A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue a... |
| CVE-2024-12771 | HIGH | 8.8 | 0.3% | Dec 21, 2024 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a... |
| CVE-2024-12721 | HIGH | 7.2 | 0.7% | Dec 21, 2024 | The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to... |
| CVE-2024-12066 | HIGH | 8.8 | 0.9% | Dec 21, 2024 | The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ... |
| CVE-2024-11977 | HIGH | 7.3 | 0.6% | Dec 21, 2024 | The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-56335 | HIGH | 7.5 | 0.3% | Dec 20, 2024 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve... |
| CVE-2024-56334 | HIGH | 7.8 | 0.7% | Dec 20, 2024 | systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when ... |
| CVE-2024-56329 | HIGH | 8.9 | 0.5% | Dec 20, 2024 | Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffo... |
| CVE-2024-12867 | HIGH | 8.8 | 0.5% | Dec 20, 2024 | Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthent... |
| CVE-2024-37758 | HIGH | 8.8 | 0.3% | Dec 20, 2024 | Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attacker... |
| CVE-2024-12677 | HIGH | 8.5 | 0.3% | Dec 20, 2024 | Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code. |
| CVE-2024-55470 | HIGH | 7.5 | 0.4% | Dec 20, 2024 | Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can ... |
| CVE-2024-10385 | HIGH | 8.6 | 0.6% | Dec 20, 2024 | Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-p... |
| CVE-2024-56356 | HIGH | 7.1 | 0.2% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack |
| CVE-2024-56351 | HIGH | 8.8 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now