2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9849 | HIGH | 8.8 | 1.2% | Nov 16, 2024 | The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file up... |
| CVE-2024-9839 | HIGH | 7.3 | 0.6% | Nov 16, 2024 | The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inc... |
| CVE-2024-9192 | HIGH | 8.8 | 0.6% | Nov 16, 2024 | The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due t... |
| CVE-2024-11263 | HIGH | 8.4 | 0.2% | Nov 15, 2024 | When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past t... |
| CVE-2024-11262 | HIGH | 7.8 | 0.4% | Nov 15, 2024 | A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affect... |
| CVE-2024-9500 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer c... |
| CVE-2024-38370 | HIGH | 7.5 | 0.4% | Nov 15, 2024 | GLPI is a free asset and IT management software package. Starting in 9.2.0 and prior to 11.0.0, it is possible to downlo... |
| CVE-2024-49060 | HIGH | 8.8 | 0.4% | Nov 15, 2024 | Azure Stack HCI Elevation of Privilege Vulnerability |
| CVE-2024-44759 | HIGH | 7.5 | 0.4% | Nov 15, 2024 | An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 all... |
| CVE-2024-51141 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAut... |
| CVE-2024-45969 | HIGH | 7.5 | 0.5% | Nov 15, 2024 | NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e35... |
| CVE-2024-45608 | HIGH | 8.8 | 0.5% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing it... |
| CVE-2024-41679 | HIGH | 8.8 | 0.5% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability... |
| CVE-2024-24431 | HIGH | 7.5 | 0.6% | Nov 15, 2024 | A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service... |
| CVE-2024-24426 | HIGH | 7.5 | 0.5% | Nov 15, 2024 | Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation ... |
| CVE-2024-52510 | HIGH | 7.5 | 0.7% | Nov 15, 2024 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client... |
| CVE-2024-52508 | HIGH | 8.1 | 0.7% | Nov 15, 2024 | Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mai... |
| CVE-2024-46467 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical f... |
| CVE-2024-46466 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission)... |
| CVE-2024-46465 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical file... |
| CVE-2024-46463 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical file... |
| CVE-2024-46462 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical fil... |
| CVE-2024-40638 | HIGH | 8.8 | 37.0% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulner... |
| CVE-2024-11251 | HIGH | 8.8 | 0.5% | Nov 15, 2024 | A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some un... |
| CVE-2024-52525 | HIGH | 7.5 | 0.3% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unen... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now