2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56051 | HIGH | 8.8 | 0.4% | Dec 18, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Inj... |
| CVE-2024-56050 | HIGH | 8.8 | 0.7% | Dec 18, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell... |
| CVE-2024-56049 | HIGH | 8.5 | 0.4% | Dec 18, 2024 | Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLM... |
| CVE-2024-56048 | HIGH | 8.8 | 0.6% | Dec 18, 2024 | Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constra... |
| CVE-2024-56047 | HIGH | 8.8 | 0.6% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS w... |
| CVE-2024-55953 | HIGH | 8.1 | 1.0% | Dec 18, 2024 | DataEase is an open source business analytics tool. Authenticated users can read and deserialize arbitrary files through... |
| CVE-2024-55952 | HIGH | 8.8 | 0.9% | Dec 18, 2024 | DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JD... |
| CVE-2024-54381 | HIGH | 7.1 | 0.4% | Dec 18, 2024 | Missing Authorization vulnerability in Dotstore Advance Menu Manager advance-menu-manager.This issue affects Advance Men... |
| CVE-2024-49202 | HIGH | 7.6 | 0.3% | Dec 18, 2024 | Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed ... |
| CVE-2024-47040 | HIGH | 7.8 | 0.2% | Dec 18, 2024 | There is a possible UAF due to a logic error in the code. This could lead to local escalation of privilege with no addit... |
| CVE-2024-47038 | HIGH | 7.8 | 0.2% | Dec 18, 2024 | In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a missing bounds chec... |
| CVE-2024-55088 | HIGH | 8.8 | 0.2% | Dec 18, 2024 | GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module. |
| CVE-2024-55086 | HIGH | 7.2 | 0.4% | Dec 18, 2024 | In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in downlo... |
| CVE-2024-49576 | HIGH | 8.8 | 1.1% | Dec 18, 2024 | A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A spe... |
| CVE-2024-47810 | HIGH | 8.8 | 1.3% | Dec 18, 2024 | A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially craft... |
| CVE-2024-47119 | HIGH | 7.5 | 0.3% | Dec 18, 2024 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow... |
| CVE-2024-48889 | HIGH | 7.2 | 1.7% | Dec 18, 2024 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2024-56016 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maartenhemmes Imag... |
| CVE-2024-56010 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Devi... |
| CVE-2024-56008 | HIGH | 7.5 | 0.4% | Dec 18, 2024 | Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality... |
| CVE-2024-55985 | HIGH | 8.5 | 0.5% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ydesignservices YD... |
| CVE-2024-55984 | HIGH | 8.5 | 0.5% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susheelhbti Saksh ... |
| CVE-2024-55983 | HIGH | 8.5 | 0.4% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PowerFormBuilder P... |
| CVE-2024-55975 | HIGH | 8.5 | 0.4% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rohit Urane Dr Aff... |
| CVE-2024-54350 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hjyl hmd hmd allow... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now