2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56310 | HIGH | 8.8 | 0.2% | Dec 22, 2024 | REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery... |
| CVE-2024-12891 | HIGH | 8.8 | 0.5% | Dec 22, 2024 | A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an ... |
| CVE-2024-12890 | HIGH | 8.8 | 0.5% | Dec 22, 2024 | A vulnerability was found in code-projects Online Exam Mastering System 1.0. It has been rated as critical. This issue a... |
| CVE-2024-12771 | HIGH | 8.8 | 0.3% | Dec 21, 2024 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a... |
| CVE-2024-12721 | HIGH | 7.2 | 0.7% | Dec 21, 2024 | The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to... |
| CVE-2024-12066 | HIGH | 8.8 | 0.9% | Dec 21, 2024 | The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ... |
| CVE-2024-11977 | HIGH | 7.3 | 0.6% | Dec 21, 2024 | The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-56335 | HIGH | 7.5 | 0.3% | Dec 20, 2024 | vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve... |
| CVE-2024-56334 | HIGH | 7.8 | 0.7% | Dec 20, 2024 | systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when ... |
| CVE-2024-56329 | HIGH | 8.9 | 0.5% | Dec 20, 2024 | Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffo... |
| CVE-2024-12867 | HIGH | 8.8 | 0.5% | Dec 20, 2024 | Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthent... |
| CVE-2024-37758 | HIGH | 8.8 | 0.3% | Dec 20, 2024 | Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attacker... |
| CVE-2024-12677 | HIGH | 8.5 | 0.3% | Dec 20, 2024 | Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code. |
| CVE-2024-55470 | HIGH | 7.5 | 0.4% | Dec 20, 2024 | Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can ... |
| CVE-2024-10385 | HIGH | 8.6 | 0.6% | Dec 20, 2024 | Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-p... |
| CVE-2024-56356 | HIGH | 7.1 | 0.2% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack |
| CVE-2024-56351 | HIGH | 8.8 | 0.3% | Dec 20, 2024 | In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles |
| CVE-2024-40695 | HIGH | 8 | 0.4% | Dec 20, 2024 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file uplo... |
| CVE-2024-28767 | HIGH | 8.8 | 0.6% | Dec 20, 2024 | IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated at... |
| CVE-2024-11297 | HIGH | 7.5 | 0.6% | Dec 20, 2024 | The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to Sensitive Information ... |
| CVE-2024-21549 | HIGH | 8.6 | 0.6% | Dec 20, 2024 | Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL ... |
| CVE-2024-44195 | HIGH | 7.5 | 0.7% | Dec 20, 2024 | A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to r... |
| CVE-2024-54538 | HIGH | 7.5 | 0.9% | Dec 20, 2024 | A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.... |
| CVE-2024-12831 | HIGH | 7.8 | 0.2% | Dec 20, 2024 | Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local... |
| CVE-2024-12830 | HIGH | 7.3 | 1.0% | Dec 20, 2024 | Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows rem... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now