2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13394 | MEDIUM | 6.4 | 0.4% | Jan 15, 2025 | The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortco... |
| CVE-2024-13334 | MEDIUM | 6.1 | 0.3% | Jan 15, 2025 | The Car Demon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_condition' parameter ... |
| CVE-2024-57760 | MEDIUM | 6.5 | 0.4% | Jan 15, 2025 | JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CG... |
| CVE-2024-53277 | MEDIUM | 5.4 | 0.3% | Jan 14, 2025 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In some cases, form messages can contain HT... |
| CVE-2024-47605 | MEDIUM | 5.4 | 1.1% | Jan 14, 2025 | silverstripe-asset-admin is a silverstripe assets gallery for asset management. When using the "insert media" functional... |
| CVE-2024-50861 | MEDIUM | 6.1 | 0.8% | Jan 14, 2025 | The ip_mod_dns_key_form.cgi request in GestioIP v3.5.7 is vulnerable to Stored XSS. An attacker can inject malicious cod... |
| CVE-2024-50859 | MEDIUM | 4.8 | 0.8% | Jan 14, 2025 | The ip_import_acl_csv request in GestioIP v3.5.7 is vulnerable to Reflected XSS. When a user uploads an improperly forma... |
| CVE-2024-50857 | MEDIUM | 4.8 | 1.2% | Jan 14, 2025 | The ip_do_job request in GestioIP v3.5.7 is vulnerable to Cross-Site Scripting (XSS). It allows data exfiltration and en... |
| CVE-2024-45102 | MEDIUM | 6.8 | 0.2% | Jan 14, 2025 | A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their ... |
| CVE-2024-10254 | MEDIUM | 4.7 | 0.1% | Jan 14, 2025 | A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could al... |
| CVE-2024-10253 | MEDIUM | 4.7 | 0.1% | Jan 14, 2025 | A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a loc... |
| CVE-2024-55945 | MEDIUM | 6.5 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55923 | MEDIUM | 4.3 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55922 | MEDIUM | 5.4 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55920 | MEDIUM | 4.3 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55894 | MEDIUM | 5.4 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55893 | MEDIUM | 4.3 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55892 | MEDIUM | 6.1 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse e... |
| CVE-2024-55891 | MEDIUM | 5.3 | 0.3% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has ... |
| CVE-2024-50349 | MEDIUM | 4.7 | 0.6% | Jan 14, 2025 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-... |
| CVE-2024-12747 | MEDIUM | 5.6 | 0.4% | Jan 14, 2025 | A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rs... |
| CVE-2024-12086 | MEDIUM | 6.8 | 1.8% | Jan 14, 2025 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's mach... |
| CVE-2024-53563 | MEDIUM | 5.4 | 0.2% | Jan 14, 2025 | A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to ex... |
| CVE-2024-52898 | MEDIUM | 6.2 | 0.2% | Jan 14, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a ... |
| CVE-2024-45627 | MEDIUM | 5.9 | 0.3% | Jan 14, 2025 | In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql J... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now