2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52914 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed tr... |
| CVE-2024-52912 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offse... |
| CVE-2024-0793 | HIGH | 7.7 | 0.6% | Nov 17, 2024 | A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking... |
| CVE-2024-52876 | HIGH | 7.5 | 0.5% | Nov 17, 2024 | Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows una... |
| CVE-2024-52872 | HIGH | 7.5 | 0.4% | Nov 17, 2024 | In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions. |
| CVE-2024-52871 | HIGH | 7.5 | 0.4% | Nov 17, 2024 | In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting. |
| CVE-2024-52867 | HIGH | 8.1 | 0.2% | Nov 17, 2024 | guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users b... |
| CVE-2024-52415 | HIGH | 8.8 | 0.2% | Nov 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object I... |
| CVE-2024-9887 | HIGH | 7.2 | 0.5% | Nov 16, 2024 | The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via th... |
| CVE-2024-10645 | HIGH | 7.5 | 0.5% | Nov 16, 2024 | The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in ... |
| CVE-2024-10728 | HIGH | 8.8 | 36.5% | Nov 16, 2024 | The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plug... |
| CVE-2024-9935 | HIGH | 7.5 | 7.5% | Nov 16, 2024 | The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions ... |
| CVE-2024-9849 | HIGH | 8.8 | 1.2% | Nov 16, 2024 | The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file up... |
| CVE-2024-9839 | HIGH | 7.3 | 0.6% | Nov 16, 2024 | The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc... |
| CVE-2024-9192 | HIGH | 8.8 | 0.6% | Nov 16, 2024 | The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due t... |
| CVE-2024-11263 | HIGH | 8.4 | 0.2% | Nov 15, 2024 | When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past t... |
| CVE-2024-11262 | HIGH | 7.8 | 0.4% | Nov 15, 2024 | A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affect... |
| CVE-2024-9500 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer c... |
| CVE-2024-38370 | HIGH | 7.5 | 0.4% | Nov 15, 2024 | GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to downlo... |
| CVE-2024-49060 | HIGH | 8.8 | 0.4% | Nov 15, 2024 | Azure Stack HCI Elevation of Privilege Vulnerability |
| CVE-2024-44759 | HIGH | 7.5 | 0.4% | Nov 15, 2024 | An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 all... |
| CVE-2024-51141 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAut... |
| CVE-2024-45969 | HIGH | 7.5 | 0.5% | Nov 15, 2024 | NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e35... |
| CVE-2024-45608 | HIGH | 8.8 | 0.5% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing it... |
| CVE-2024-41679 | HIGH | 8.8 | 0.5% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now