2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52449 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Navneil Naicer Bootscrap... |
| CVE-2024-52448 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate ... |
| CVE-2024-52447 | HIGH | 8.6 | 0.6% | Nov 20, 2024 | Path Traversal: '.../...//' vulnerability in corporatezen222 Contact Page With Google Map contact-page-with-google-map a... |
| CVE-2024-52446 | HIGH | 8.8 | 0.2% | Nov 20, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Buying Buddy Buying Buddy IDX CRM buying-buddy-idx-crm allows Object ... |
| CVE-2024-52445 | HIGH | 8.8 | 0.5% | Nov 20, 2024 | Deserialization of Untrusted Data vulnerability in ModelTheme QRMenu Restaurant QR Menu Lite qrmenu-lite allows Object I... |
| CVE-2024-52444 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom P... |
| CVE-2024-52438 | HIGH | 8.8 | 0.5% | Nov 20, 2024 | Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escala... |
| CVE-2024-52437 | HIGH | 8.8 | 0.5% | Nov 20, 2024 | Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Pr... |
| CVE-2024-45690 | HIGH | 7.5 | 0.4% | Nov 20, 2024 | A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts... |
| CVE-2024-10382 | HIGH | 7.5 | 0.2% | Nov 20, 2024 | There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization l... |
| CVE-2024-11494 | HIGH | 7.5 | 0.7% | Nov 20, 2024 | **UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version... |
| CVE-2024-48895 | HIGH | 8.8 | 1.0% | Nov 20, 2024 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo... |
| CVE-2024-10900 | HIGH | 8.1 | 0.5% | Nov 20, 2024 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2024-10899 | HIGH | 7.3 | 0.6% | Nov 20, 2024 | The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio... |
| CVE-2024-10855 | HIGH | 8.1 | 0.5% | Nov 20, 2024 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that... |
| CVE-2024-44308 | HIGH | 8.8 | 9.2% | Nov 20, 2024 | The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18... |
| CVE-2024-44307 | HIGH | 7.8 | 0.2% | Nov 20, 2024 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app ma... |
| CVE-2024-44306 | HIGH | 7.8 | 0.2% | Nov 20, 2024 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app ma... |
| CVE-2024-51669 | HIGH | 8.8 | 0.2% | Nov 19, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Kalmang Dynamic Widgets dynamic-widgets.This issue affects Dynamic Wi... |
| CVE-2024-52359 | HIGH | 8.8 | 0.3% | Nov 19, 2024 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions ... |
| CVE-2024-45422 | HIGH | 7.5 | 0.5% | Nov 19, 2024 | Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated user to conduct a denial o... |
| CVE-2024-45419 | HIGH | 7.5 | 0.5% | Nov 19, 2024 | Improper input validation in some Zoom Apps may allow an unauthenticated user to conduct a disclosure of information via... |
| CVE-2024-11395 | HIGH | 8.8 | 0.4% | Nov 19, 2024 | Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-51503 | HIGH | 8.8 | 4.0% | Nov 19, 2024 | A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an at... |
| CVE-2024-21697 | HIGH | 8.8 | 0.7% | Nov 19, 2024 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now