2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35141 | HIGH | 7.8 | 0.2% | Dec 19, 2024 | IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to exe... |
| CVE-2024-56319 | HIGH | 7.5 | 0.5% | Dec 18, 2024 | In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userla... |
| CVE-2024-56318 | HIGH | 7.5 | 0.6% | Dec 18, 2024 | In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer d... |
| CVE-2024-56317 | HIGH | 7.5 | 0.4% | Dec 18, 2024 | In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries ... |
| CVE-2024-56116 | HIGH | 8.8 | 0.4% | Dec 18, 2024 | A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator ... |
| CVE-2024-55506 | HIGH | 8.8 | 0.7% | Dec 18, 2024 | An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to ex... |
| CVE-2024-53580 | HIGH | 7.5 | 0.9% | Dec 18, 2024 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. |
| CVE-2024-41159 | HIGH | 7.1 | 0.8% | Dec 18, 2024 | A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage ... |
| CVE-2024-55505 | HIGH | 8.8 | 0.7% | Dec 18, 2024 | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-vie... |
| CVE-2024-12695 | HIGH | 8.8 | 0.4% | Dec 18, 2024 | Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code i... |
| CVE-2024-12694 | HIGH | 8.8 | 0.3% | Dec 18, 2024 | Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit ... |
| CVE-2024-12693 | HIGH | 8.8 | 0.4% | Dec 18, 2024 | Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrar... |
| CVE-2024-12692 | HIGH | 8.8 | 6.1% | Dec 18, 2024 | Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2024-12686 | HIGH | 7.2 | 13.8% | Dec 18, 2024 | A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacke... |
| CVE-2024-53271 | HIGH | 7.1 | 0.6% | Dec 18, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle... |
| CVE-2024-53270 | HIGH | 7.5 | 0.7% | Dec 18, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to... |
| CVE-2024-53269 | HIGH | 7.5 | 0.7% | Dec 18, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then t... |
| CVE-2024-49363 | HIGH | 7.4 | 0.3% | Dec 18, 2024 | Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in gith... |
| CVE-2024-36694 | HIGH | 7.2 | 0.9% | Dec 18, 2024 | OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function. |
| CVE-2024-12741 | HIGH | 8.4 | 4.2% | Dec 18, 2024 | A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Succ... |
| CVE-2024-56057 | HIGH | 8.8 | 0.5% | Dec 18, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell... |
| CVE-2024-56055 | HIGH | 8.8 | 0.5% | Dec 18, 2024 | Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLM... |
| CVE-2024-56054 | HIGH | 8.8 | 0.6% | Dec 18, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell... |
| CVE-2024-56053 | HIGH | 8.8 | 0.4% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS w... |
| CVE-2024-56052 | HIGH | 8.8 | 0.7% | Dec 18, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now