2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12200 | HIGH | 7.8 | 0.3% | Dec 17, 2024 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability... |
| CVE-2024-12199 | HIGH | 7.8 | 0.3% | Dec 17, 2024 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability... |
| CVE-2024-12198 | HIGH | 7.8 | 0.5% | Dec 17, 2024 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability... |
| CVE-2024-12197 | HIGH | 7.8 | 0.3% | Dec 17, 2024 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability... |
| CVE-2024-12194 | HIGH | 7.8 | 0.3% | Dec 17, 2024 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A... |
| CVE-2024-12193 | HIGH | 7.8 | 0.3% | Dec 17, 2024 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability... |
| CVE-2024-12192 | HIGH | 7.8 | 0.3% | Dec 17, 2024 | A maliciously crafted DWF file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability.... |
| CVE-2024-12191 | HIGH | 7.8 | 0.3% | Dec 17, 2024 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability... |
| CVE-2024-12179 | HIGH | 7.8 | 0.3% | Dec 17, 2024 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vul... |
| CVE-2024-12178 | HIGH | 7.8 | 0.3% | Dec 17, 2024 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A... |
| CVE-2024-11422 | HIGH | 7.8 | 0.4% | Dec 17, 2024 | A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability... |
| CVE-2024-10476 | HIGH | 8 | 0.2% | Dec 17, 2024 | Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be ab... |
| CVE-2024-36832 | HIGH | 7.5 | 0.4% | Dec 17, 2024 | A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via... |
| CVE-2024-8326 | HIGH | 8.8 | 0.6% | Dec 17, 2024 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin... |
| CVE-2024-12293 | HIGH | 8.8 | 0.3% | Dec 17, 2024 | The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2024-11999 | HIGH | 8.8 | 0.6% | Dec 17, 2024 | CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the devic... |
| CVE-2024-9624 | HIGH | 7.6 | 0.4% | Dec 17, 2024 | The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu... |
| CVE-2024-38499 | HIGH | 8.8 | 0.2% | Dec 17, 2024 | CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This woul... |
| CVE-2024-56017 | HIGH | 7.1 | 0.1% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects... |
| CVE-2024-52949 | HIGH | 7.5 | 0.7% | Dec 16, 2024 | iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control th... |
| CVE-2024-37775 | HIGH | 7.5 | 0.4% | Dec 16, 2024 | Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location wh... |
| CVE-2024-37774 | HIGH | 8 | 0.2% | Dec 16, 2024 | A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their priv... |
| CVE-2024-55104 | HIGH | 7.2 | 0.5% | Dec 16, 2024 | Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin... |
| CVE-2024-55103 | HIGH | 7.2 | 0.6% | Dec 16, 2024 | Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.... |
| CVE-2024-12666 | HIGH | 8.8 | 0.5% | Dec 16, 2024 | A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an un... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now