2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11241 | HIGH | 7.5 | 0.6% | Nov 15, 2024 | A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as critical. Affected by this vulne... |
| CVE-2024-10311 | HIGH | 8.8 | 0.4% | Nov 15, 2024 | The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and i... |
| CVE-2024-45784 | HIGH | 7.5 | 1.3% | Nov 15, 2024 | Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in tas... |
| CVE-2024-49778 | HIGH | 8.8 | 0.6% | Nov 14, 2024 | A heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service ... |
| CVE-2024-49777 | HIGH | 8.8 | 0.6% | Nov 14, 2024 | A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service ... |
| CVE-2024-41209 | HIGH | 8.8 | 0.6% | Nov 14, 2024 | A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service ... |
| CVE-2024-51659 | HIGH | 7.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XS... |
| CVE-2024-51658 | HIGH | 7.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.Thi... |
| CVE-2024-50968 | HIGH | 7.5 | 0.8% | Nov 14, 2024 | A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.... |
| CVE-2024-51687 | HIGH | 7.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This is... |
| CVE-2024-51684 | HIGH | 7.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issu... |
| CVE-2024-51688 | HIGH | 7.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verific... |
| CVE-2024-10397 | HIGH | 7.8 | 0.4% | Nov 14, 2024 | A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code. |
| CVE-2024-10394 | HIGH | 7.8 | 0.2% | Nov 14, 2024 | A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing th... |
| CVE-2024-3760 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bom... |
| CVE-2024-5125 | HIGH | 7.3 | 0.3% | Nov 14, 2024 | parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input ... |
| CVE-2024-52396 | HIGH | 8.8 | 0.6% | Nov 14, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-edi... |
| CVE-2024-52393 | HIGH | 7.2 | 0.5% | Nov 14, 2024 | Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-... |
| CVE-2024-52383 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in On... |
| CVE-2024-52381 | HIGH | 8.1 | 0.6% | Nov 14, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-52378 | HIGH | 7.5 | 0.5% | Nov 14, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 DigiPass digipass... |
| CVE-2024-52371 | HIGH | 8.6 | 0.6% | Nov 14, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DonnellC Global Gateway ... |
| CVE-2024-50831 | HIGH | 7.2 | 0.4% | Nov 14, 2024 | A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the usernam... |
| CVE-2024-50830 | HIGH | 7.2 | 0.4% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Proje... |
| CVE-2024-50829 | HIGH | 7.2 | 0.4% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now