2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51364 | HIGH | 8.8 | 0.7% | Nov 21, 2024 | An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a... |
| CVE-2024-53432 | HIGH | 7.5 | 0.7% | Nov 21, 2024 | While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in ... |
| CVE-2024-53335 | HIGH | 7.8 | 0.3% | Nov 21, 2024 | TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi. |
| CVE-2024-53334 | HIGH | 8.8 | 0.7% | Nov 21, 2024 | TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi. |
| CVE-2024-52287 | HIGH | 7.2 | 0.6% | Nov 21, 2024 | authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was pos... |
| CVE-2024-48288 | HIGH | 8 | 10.3% | Nov 21, 2024 | TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification... |
| CVE-2024-48286 | HIGH | 8 | 12.4% | Nov 21, 2024 | Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function. |
| CVE-2024-52799 | HIGH | 8.2 | 0.2% | Nov 21, 2024 | Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workfl... |
| CVE-2024-53429 | HIGH | 7.5 | 0.7% | Nov 21, 2024 | Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash. |
| CVE-2024-28027 | HIGH | 7.2 | 7.5% | Nov 21, 2024 | Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies... |
| CVE-2024-28026 | HIGH | 7.2 | 5.8% | Nov 21, 2024 | Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies... |
| CVE-2024-28025 | HIGH | 7.2 | 7.5% | Nov 21, 2024 | Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies... |
| CVE-2024-21786 | HIGH | 7.2 | 10.5% | Nov 21, 2024 | An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies ... |
| CVE-2024-7026 | HIGH | 7.5 | 0.6% | Nov 21, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informati... |
| CVE-2024-11088 | HIGH | 7.5 | 0.6% | Nov 21, 2024 | The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2024-11589 | HIGH | 8.8 | 0.7% | Nov 21, 2024 | A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulne... |
| CVE-2024-11588 | HIGH | 7.5 | 0.8% | Nov 21, 2024 | A vulnerability was found in AVL-DiTEST-DiagDev libdoip 1.0.0. It has been rated as problematic. This issue affects the ... |
| CVE-2024-7517 | HIGH | 7.8 | 0.6% | Nov 21, 2024 | A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms... |
| CVE-2024-52797 | HIGH | 7.5 | 0.9% | Nov 21, 2024 | Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and... |
| CVE-2024-45663 | HIGH | 7.5 | 0.7% | Nov 21, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of serv... |
| CVE-2024-11409 | HIGH | 7.2 | 1.1% | Nov 21, 2024 | The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1... |
| CVE-2024-10898 | HIGH | 8.8 | 1.3% | Nov 21, 2024 | The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in... |
| CVE-2024-10788 | HIGH | 7.2 | 0.8% | Nov 21, 2024 | The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2024-10403 | HIGH | 7.5 | 0.6% | Nov 21, 2024 | Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFT... |
| CVE-2024-10400 | HIGH | 7.5 | 82.6% | Nov 21, 2024 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now