2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51162 | HIGH | 8.8 | 0.6% | Nov 20, 2024 | An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the off... |
| CVE-2024-11487 | HIGH | 8.8 | 0.4% | Nov 20, 2024 | A vulnerability has been found in Code4Berry Decoration Management System 1.0 and classified as critical. This vulnerabi... |
| CVE-2024-11485 | HIGH | 8.1 | 0.3% | Nov 20, 2024 | A vulnerability, which was classified as critical, has been found in Code4Berry Decoration Management System 1.0. Affect... |
| CVE-2024-11484 | HIGH | 8.8 | 0.4% | Nov 20, 2024 | A vulnerability classified as critical was found in Code4Berry Decoration Management System 1.0. Affected by this vulner... |
| CVE-2024-52598 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | 2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconne... |
| CVE-2024-52473 | HIGH | 7.1 | 0.3% | Nov 20, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sandeep Verma HTML... |
| CVE-2024-52472 | HIGH | 7.1 | 0.3% | Nov 20, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weather Atlas Weat... |
| CVE-2024-52470 | HIGH | 7.1 | 0.3% | Nov 20, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brainvireinfo Dyna... |
| CVE-2024-51208 | HIGH | 7.2 | 0.4% | Nov 20, 2024 | File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to ... |
| CVE-2024-10913 | HIGH | 8.8 | 0.6% | Nov 20, 2024 | The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via des... |
| CVE-2024-11495 | HIGH | 7.8 | 0.1% | Nov 20, 2024 | Buffer overflow vulnerability in OllyDbg, version 1.10, which could allow a local attacker to execute arbitrary code due... |
| CVE-2024-52451 | HIGH | 8.2 | 0.2% | Nov 20, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in aaronrobbins Post Ideas post-ideas allows SQL Injection.This issue af... |
| CVE-2024-52450 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-52449 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Navneil Naicer Bootscrap... |
| CVE-2024-52448 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate ... |
| CVE-2024-52447 | HIGH | 8.6 | 0.6% | Nov 20, 2024 | Path Traversal: '.../...//' vulnerability in corporatezen222 Contact Page With Google Map contact-page-with-google-map a... |
| CVE-2024-52446 | HIGH | 8.8 | 0.2% | Nov 20, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Buying Buddy Buying Buddy IDX CRM buying-buddy-idx-crm allows Object ... |
| CVE-2024-52445 | HIGH | 8.8 | 0.5% | Nov 20, 2024 | Deserialization of Untrusted Data vulnerability in ModelTheme QRMenu Restaurant QR Menu Lite qrmenu-lite allows Object I... |
| CVE-2024-52444 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom P... |
| CVE-2024-52438 | HIGH | 8.8 | 0.5% | Nov 20, 2024 | Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escala... |
| CVE-2024-52437 | HIGH | 8.8 | 0.5% | Nov 20, 2024 | Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Pr... |
| CVE-2024-45690 | HIGH | 7.5 | 0.4% | Nov 20, 2024 | A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts... |
| CVE-2024-10382 | HIGH | 7.5 | 0.2% | Nov 20, 2024 | There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization l... |
| CVE-2024-11494 | HIGH | 7.5 | 0.7% | Nov 20, 2024 | **UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version... |
| CVE-2024-48895 | HIGH | 8.8 | 1.0% | Nov 20, 2024 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now