2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21786 | HIGH | 7.2 | 10.5% | Nov 21, 2024 | An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies ... |
| CVE-2024-7026 | HIGH | 7.5 | 0.6% | Nov 21, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informati... |
| CVE-2024-11088 | HIGH | 7.5 | 0.6% | Nov 21, 2024 | The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2024-11589 | HIGH | 8.8 | 0.7% | Nov 21, 2024 | A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulne... |
| CVE-2024-11588 | HIGH | 7.5 | 0.8% | Nov 21, 2024 | A vulnerability was found in AVL-DiTEST-DiagDev libdoip 1.0.0. It has been rated as problematic. This issue affects the ... |
| CVE-2024-7517 | HIGH | 7.8 | 0.6% | Nov 21, 2024 | A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms... |
| CVE-2024-52797 | HIGH | 7.5 | 0.9% | Nov 21, 2024 | Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and... |
| CVE-2024-45663 | HIGH | 7.5 | 0.7% | Nov 21, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of serv... |
| CVE-2024-11409 | HIGH | 7.2 | 1.1% | Nov 21, 2024 | The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1... |
| CVE-2024-10898 | HIGH | 8.8 | 1.3% | Nov 21, 2024 | The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in... |
| CVE-2024-10788 | HIGH | 7.2 | 0.8% | Nov 21, 2024 | The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2024-10403 | HIGH | 7.5 | 0.6% | Nov 21, 2024 | Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFT... |
| CVE-2024-10400 | HIGH | 7.5 | 82.6% | Nov 21, 2024 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up t... |
| CVE-2024-9875 | HIGH | 7.1 | 0.2% | Nov 21, 2024 | Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerabilit... |
| CVE-2024-52581 | HIGH | 7.5 | 0.8% | Nov 20, 2024 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parse... |
| CVE-2024-48986 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci pac... |
| CVE-2024-48982 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci pac... |
| CVE-2024-48536 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the compa... |
| CVE-2024-48530 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a D... |
| CVE-2024-48985 | HIGH | 7.5 | 0.4% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the len... |
| CVE-2024-48983 | HIGH | 7.5 | 0.4% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the len... |
| CVE-2024-48981 | HIGH | 7.5 | 0.3% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the len... |
| CVE-2024-52739 | HIGH | 8 | 9.1% | Nov 20, 2024 | D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_... |
| CVE-2024-52769 | HIGH | 7.2 | 0.7% | Nov 20, 2024 | An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to exe... |
| CVE-2024-51163 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now