2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12829 | HIGH | 8.8 | 1.3% | Dec 20, 2024 | Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remo... |
| CVE-2024-54663 | HIGH | 7.5 | 0.6% | Dec 19, 2024 | An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Incl... |
| CVE-2024-12700 | HIGH | 8.8 | 0.6% | Dec 19, 2024 | There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to up... |
| CVE-2024-12729 | HIGH | 8.8 | 1.3% | Dec 19, 2024 | A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sopho... |
| CVE-2024-12672 | HIGH | 7.3 | 0.2% | Dec 19, 2024 | A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the... |
| CVE-2024-12175 | HIGH | 7.8 | 0.3% | Dec 19, 2024 | Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat... |
| CVE-2024-11364 | HIGH | 7.3 | 0.3% | Dec 19, 2024 | Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow ... |
| CVE-2024-11157 | HIGH | 7.3 | 0.2% | Dec 19, 2024 | A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the... |
| CVE-2024-12111 | HIGH | 8 | 0.4% | Dec 19, 2024 | In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Ac... |
| CVE-2024-56200 | HIGH | 8.6 | 0.6% | Dec 19, 2024 | Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image pr... |
| CVE-2024-55196 | HIGH | 7.5 | 0.4% | Dec 19, 2024 | Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cl... |
| CVE-2024-38819 | HIGH | 7.5 | 54.9% | Dec 19, 2024 | Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to pa... |
| CVE-2024-12790 | HIGH | 8.2 | 0.5% | Dec 19, 2024 | A vulnerability was found in code-projects Hostel Management Site 1.0. It has been declared as problematic. This vulnera... |
| CVE-2024-9154 | HIGH | 8.6 | 0.6% | Dec 19, 2024 | A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. T... |
| CVE-2024-55082 | HIGH | 7.5 | 0.5% | Dec 19, 2024 | A Server-Side Request Forgery (SSRF) in the endpoint http://{your-server}/url-to-pdf of Stirling-PDF 0.35.1 allows attac... |
| CVE-2024-54790 | HIGH | 7.5 | 0.6% | Dec 19, 2024 | A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remo... |
| CVE-2024-25131 | HIGH | 8.8 | 0.8% | Dec 19, 2024 | A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-priv... |
| CVE-2024-12786 | HIGH | 8.5 | 0.2% | Dec 19, 2024 | A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected i... |
| CVE-2024-12785 | HIGH | 8.8 | 0.5% | Dec 19, 2024 | A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been declared as critical. Affected by t... |
| CVE-2024-12782 | HIGH | 7.3 | 0.7% | Dec 19, 2024 | A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 an... |
| CVE-2024-12569 | HIGH | 7.8 | 0.1% | Dec 19, 2024 | Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allow... |
| CVE-2024-4230 | HIGH | 7.8 | 0.2% | Dec 19, 2024 | External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and ... |
| CVE-2024-4229 | HIGH | 7.8 | 0.2% | Dec 19, 2024 | Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecros... |
| CVE-2024-11740 | HIGH | 7.3 | 1.9% | Dec 19, 2024 | The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and ... |
| CVE-2024-51532 | HIGH | 7.1 | 0.3% | Dec 19, 2024 | Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerabi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now