2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52538 | HIGH | 8.8 | 0.4% | Dec 10, 2024 | Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Impr... |
| CVE-2024-47977 | HIGH | 8.8 | 0.6% | Dec 10, 2024 | Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Impr... |
| CVE-2024-10959 | HIGH | 7.3 | 0.6% | Dec 10, 2024 | The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to a... |
| CVE-2024-47946 | HIGH | 7.2 | 1.1% | Dec 10, 2024 | If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted val... |
| CVE-2024-28138 | HIGH | 7.3 | 0.9% | Dec 10, 2024 | An unauthenticated attacker with network access to the affected device's web interface can execute any system command vi... |
| CVE-2024-21542 | HIGH | 8.6 | 1.1% | Dec 10, 2024 | Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due ... |
| CVE-2024-53919 | HIGH | 7.6 | 0.4% | Dec 10, 2024 | An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmwar... |
| CVE-2024-54198 | HIGH | 8.5 | 0.6% | Dec 10, 2024 | In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function... |
| CVE-2024-54197 | HIGH | 7.2 | 0.3% | Dec 10, 2024 | SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in ... |
| CVE-2024-55634 | HIGH | 8.1 | 0.4% | Dec 10, 2024 | A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, fr... |
| CVE-2024-50628 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local ar... |
| CVE-2024-50627 | HIGH | 8.8 | 0.3% | Dec 9, 2024 | An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file u... |
| CVE-2024-50626 | HIGH | 8.8 | 0.5% | Dec 9, 2024 | An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This... |
| CVE-2024-50625 | HIGH | 8 | 0.3% | Dec 9, 2024 | An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web appl... |
| CVE-2024-54151 | HIGH | 7.5 | 0.6% | Dec 9, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to... |
| CVE-2024-54149 | HIGH | 8.4 | 0.4% | Dec 9, 2024 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to ve... |
| CVE-2024-54938 | HIGH | 7.5 | 0.5% | Dec 9, 2024 | A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to acc... |
| CVE-2024-54928 | HIGH | 7.2 | 0.5% | Dec 9, 2024 | kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php, |
| CVE-2024-54927 | HIGH | 7.2 | 0.5% | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php. |
| CVE-2024-52586 | HIGH | 7.8 | 0.2% | Dec 9, 2024 | eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version ... |
| CVE-2024-46547 | HIGH | 7.5 | 0.4% | Dec 9, 2024 | A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized... |
| CVE-2024-54933 | HIGH | 7.2 | 0.5% | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php. |
| CVE-2024-54930 | HIGH | 7.2 | 0.5% | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php. |
| CVE-2024-54922 | HIGH | 7.2 | 0.6% | Dec 9, 2024 | A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote at... |
| CVE-2024-11608 | HIGH | 7.8 | 0.2% | Dec 9, 2024 | A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now