2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45102 | MEDIUM | 6.8 | 0.2% | Jan 14, 2025 | A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their ... |
| CVE-2024-10254 | MEDIUM | 4.7 | 0.1% | Jan 14, 2025 | A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could al... |
| CVE-2024-10253 | MEDIUM | 4.7 | 0.1% | Jan 14, 2025 | A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a loc... |
| CVE-2024-55945 | MEDIUM | 6.5 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55923 | MEDIUM | 4.3 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55922 | MEDIUM | 5.4 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55920 | MEDIUM | 4.3 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55894 | MEDIUM | 5.4 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55893 | MEDIUM | 4.3 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user in... |
| CVE-2024-55892 | MEDIUM | 6.1 | 0.2% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse e... |
| CVE-2024-55891 | MEDIUM | 5.3 | 0.3% | Jan 14, 2025 | TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has ... |
| CVE-2024-50349 | MEDIUM | 4.7 | 0.6% | Jan 14, 2025 | Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-... |
| CVE-2024-12747 | MEDIUM | 5.6 | 0.4% | Jan 14, 2025 | A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rs... |
| CVE-2024-12086 | MEDIUM | 6.8 | 1.8% | Jan 14, 2025 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's mach... |
| CVE-2024-53563 | MEDIUM | 5.4 | 0.2% | Jan 14, 2025 | A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to ex... |
| CVE-2024-52898 | MEDIUM | 6.2 | 0.2% | Jan 14, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a ... |
| CVE-2024-45627 | MEDIUM | 5.9 | 0.3% | Jan 14, 2025 | In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql J... |
| CVE-2024-55000 | MEDIUM | 5.4 | 0.3% | Jan 14, 2025 | Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categori... |
| CVE-2024-39773 | MEDIUM | 5.3 | 0.8% | Jan 14, 2025 | An information disclosure vulnerability exists in the testsave.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A ... |
| CVE-2024-39363 | MEDIUM | 6.1 | 48.1% | Jan 14, 2025 | A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC300... |
| CVE-2024-56497 | MEDIUM | 6.7 | 0.6% | Jan 14, 2025 | An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail vers... |
| CVE-2024-54021 | MEDIUM | 5.8 | 0.8% | Jan 14, 2025 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fort... |
| CVE-2024-52969 | MEDIUM | 6.5 | 0.5% | Jan 14, 2025 | An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiS... |
| CVE-2024-52967 | MEDIUM | 4.8 | 0.3% | Jan 14, 2025 | An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6... |
| CVE-2024-52963 | MEDIUM | 5.9 | 0.7% | Jan 14, 2025 | A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.1... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now