2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38499 | HIGH | 8.8 | 0.2% | Dec 17, 2024 | CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This woul... |
| CVE-2024-56017 | HIGH | 7.1 | 0.1% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects... |
| CVE-2024-52949 | HIGH | 7.5 | 0.7% | Dec 16, 2024 | iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control th... |
| CVE-2024-37775 | HIGH | 7.5 | 0.4% | Dec 16, 2024 | Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location wh... |
| CVE-2024-37774 | HIGH | 8 | 0.2% | Dec 16, 2024 | A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their priv... |
| CVE-2024-55104 | HIGH | 7.2 | 0.5% | Dec 16, 2024 | Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin... |
| CVE-2024-55103 | HIGH | 7.2 | 0.6% | Dec 16, 2024 | Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.... |
| CVE-2024-12666 | HIGH | 8.8 | 0.5% | Dec 16, 2024 | A vulnerability has been found in ClassCMS up to 4.8 and classified as critical. Affected by this vulnerability is an un... |
| CVE-2024-8058 | HIGH | 7.6 | 0.3% | Dec 16, 2024 | An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ director... |
| CVE-2024-6001 | HIGH | 8.1 | 0.3% | Dec 16, 2024 | An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the abili... |
| CVE-2024-4762 | HIGH | 7.8 | 0.1% | Dec 16, 2024 | An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a l... |
| CVE-2024-54376 | HIGH | 7.5 | 0.6% | Dec 16, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-54284 | HIGH | 7.6 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedP... |
| CVE-2024-54283 | HIGH | 7.6 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedP... |
| CVE-2024-54279 | HIGH | 7.5 | 0.5% | Dec 16, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tobias Keller WP-NERD Toolki... |
| CVE-2024-54257 | HIGH | 7.1 | 0.3% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molefed allows Ref... |
| CVE-2024-54249 | HIGH | 7.1 | 0.3% | Dec 16, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jules Colle Advanc... |
| CVE-2024-56015 | HIGH | 7.1 | 0.2% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in John Godley Tidy Up allows Reflected XSS.This issue affects Tidy Up: ... |
| CVE-2024-56013 | HIGH | 8.8 | 0.6% | Dec 16, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in wovax Wovax IDX wovax-idx allows Authenticatio... |
| CVE-2024-55990 | HIGH | 7.6 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tsjippy Mollie for... |
| CVE-2024-55989 | HIGH | 7.6 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kyle M Brown WP Si... |
| CVE-2024-55987 | HIGH | 8.5 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ritesh Sanap Advan... |
| CVE-2024-55986 | HIGH | 8.5 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tiny13 Service ser... |
| CVE-2024-55979 | HIGH | 8.5 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robindkumar Wr Age... |
| CVE-2024-55974 | HIGH | 8.5 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martí Batlles Mart... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now