2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9875 | HIGH | 7.1 | 0.2% | Nov 21, 2024 | Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerabilit... |
| CVE-2024-52581 | HIGH | 7.5 | 0.8% | Nov 20, 2024 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parse... |
| CVE-2024-48986 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci pac... |
| CVE-2024-48982 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci pac... |
| CVE-2024-48536 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the compa... |
| CVE-2024-48530 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a D... |
| CVE-2024-48985 | HIGH | 7.5 | 0.4% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the len... |
| CVE-2024-48983 | HIGH | 7.5 | 0.4% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the len... |
| CVE-2024-48981 | HIGH | 7.5 | 0.3% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the len... |
| CVE-2024-52739 | HIGH | 8 | 9.1% | Nov 20, 2024 | D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_... |
| CVE-2024-52769 | HIGH | 7.2 | 0.7% | Nov 20, 2024 | An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to exe... |
| CVE-2024-51163 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker ... |
| CVE-2024-51162 | HIGH | 8.8 | 0.6% | Nov 20, 2024 | An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the off... |
| CVE-2024-11487 | HIGH | 8.8 | 0.4% | Nov 20, 2024 | A vulnerability has been found in Code4Berry Decoration Management System 1.0 and classified as critical. This vulnerabi... |
| CVE-2024-11485 | HIGH | 8.1 | 0.3% | Nov 20, 2024 | A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affect... |
| CVE-2024-11484 | HIGH | 8.8 | 0.4% | Nov 20, 2024 | A vulnerability classified as critical was found in Code4Berry Decoration Management System 1.0. Affected by this vulner... |
| CVE-2024-52598 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconne... |
| CVE-2024-52473 | HIGH | 7.1 | 0.3% | Nov 20, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sandeep Verma HTML... |
| CVE-2024-52472 | HIGH | 7.1 | 0.3% | Nov 20, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weather Atlas Weat... |
| CVE-2024-52470 | HIGH | 7.1 | 0.3% | Nov 20, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brainvireinfo Dyna... |
| CVE-2024-51208 | HIGH | 7.2 | 0.4% | Nov 20, 2024 | File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to ... |
| CVE-2024-10913 | HIGH | 8.8 | 0.6% | Nov 20, 2024 | The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via des... |
| CVE-2024-11495 | HIGH | 7.8 | 0.1% | Nov 20, 2024 | Buffer overflow vulnerability in OllyDbg, version 1.10, which could allow a local attacker to execute arbitrary code due... |
| CVE-2024-52451 | HIGH | 8.2 | 0.2% | Nov 20, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in aaronrobbins Post Ideas post-ideas allows SQL Injection.This issue af... |
| CVE-2024-52450 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now