2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-56016 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maartenhemmes Imag... |
| CVE-2024-56010 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy Devi... |
| CVE-2024-56008 | HIGH | 7.5 | 0.4% | Dec 18, 2024 | Missing Authorization vulnerability in spreadr Spreadr Woocommerce spreadr-for-woocomerce allows Accessing Functionality... |
| CVE-2024-55985 | HIGH | 8.5 | 0.5% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ydesignservices YD... |
| CVE-2024-55984 | HIGH | 8.5 | 0.5% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susheelhbti Saksh ... |
| CVE-2024-55983 | HIGH | 8.5 | 0.4% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PowerFormBuilder P... |
| CVE-2024-55975 | HIGH | 8.5 | 0.4% | Dec 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rohit Urane Dr Aff... |
| CVE-2024-54350 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hjyl hmd hmd allow... |
| CVE-2024-54270 | HIGH | 8.1 | 0.7% | Dec 18, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-51646 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saoshyant1994 Saos... |
| CVE-2024-49677 | HIGH | 7.1 | 0.3% | Dec 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Cramer Boots... |
| CVE-2024-11912 | HIGH | 7.5 | 0.5% | Dec 18, 2024 | The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_id... |
| CVE-2024-11614 | HIGH | 7.4 | 0.6% | Dec 18, 2024 | An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an un... |
| CVE-2024-54457 | HIGH | 7.2 | 0.4% | Dec 18, 2024 | Inclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE102... |
| CVE-2024-53688 | HIGH | 7.2 | 1.5% | Dec 18, 2024 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmwa... |
| CVE-2024-47397 | HIGH | 7.5 | 0.4% | Dec 18, 2024 | Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 an... |
| CVE-2024-39703 | HIGH | 8.8 | 0.7% | Dec 18, 2024 | In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted... |
| CVE-2024-56174 | HIGH | 8.1 | 0.4% | Dec 18, 2024 | In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ... |
| CVE-2024-4464 | HIGH | 7.5 | 0.5% | Dec 18, 2024 | Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-... |
| CVE-2024-21548 | HIGH | 7.5 | 0.6% | Dec 18, 2024 | Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input s... |
| CVE-2024-21547 | HIGH | 7.7 | 0.9% | Dec 18, 2024 | Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation i... |
| CVE-2024-12432 | HIGH | 8.1 | 0.5% | Dec 18, 2024 | The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalati... |
| CVE-2024-12259 | HIGH | 8.8 | 0.5% | Dec 18, 2024 | The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover i... |
| CVE-2024-12025 | HIGH | 7.5 | 2.5% | Dec 18, 2024 | The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-js... |
| CVE-2024-47480 | HIGH | 7.8 | 0.2% | Dec 18, 2024 | Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulne... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now