2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10013 | HIGH | 7.8 | 0.2% | Nov 13, 2024 | In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through... |
| CVE-2024-10012 | HIGH | 7.8 | 0.2% | Nov 13, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an i... |
| CVE-2024-50854 | HIGH | 8.8 | 0.5% | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function. |
| CVE-2024-50853 | HIGH | 8.8 | 1.6% | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function. |
| CVE-2024-50852 | HIGH | 8.8 | 1.6% | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount ... |
| CVE-2024-49506 | HIGH | 7.3 | 0.1% | Nov 13, 2024 | Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of se... |
| CVE-2024-49504 | HIGH | 7 | 0.3% | Nov 13, 2024 | grub2 allowed attackers with access to the grub shell to access files on the encrypted disks. |
| CVE-2024-48989 | HIGH | 7.5 | 0.5% | Nov 13, 2024 | A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacke... |
| CVE-2024-47574 | HIGH | 7.8 | 0.5% | Nov 13, 2024 | A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 ... |
| CVE-2024-4741 | HIGH | 7.5 | 2.9% | Nov 13, 2024 | Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously fre... |
| CVE-2024-9409 | HIGH | 7.5 | 0.8% | Nov 13, 2024 | CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive re... |
| CVE-2024-8937 | HIGH | 8.3 | 0.6% | Nov 13, 2024 | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a... |
| CVE-2024-8936 | HIGH | 8.3 | 0.5% | Nov 13, 2024 | CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory a... |
| CVE-2024-8935 | HIGH | 7.7 | 0.5% | Nov 13, 2024 | CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confide... |
| CVE-2024-10800 | HIGH | 8.8 | 0.8% | Nov 13, 2024 | The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability c... |
| CVE-2024-8933 | HIGH | 7.5 | 0.3% | Nov 13, 2024 | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t... |
| CVE-2024-10816 | HIGH | 7.5 | 1.1% | Nov 13, 2024 | The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.... |
| CVE-2024-10174 | HIGH | 7.3 | 0.6% | Nov 13, 2024 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo... |
| CVE-2024-39709 | HIGH | 7.8 | 0.3% | Nov 13, 2024 | Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Se... |
| CVE-2024-38655 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version... |
| CVE-2024-38649 | HIGH | 7.5 | 1.9% | Nov 13, 2024 | An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remot... |
| CVE-2024-37400 | HIGH | 7.5 | 2.0% | Nov 13, 2024 | An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigg... |
| CVE-2024-37398 | HIGH | 7.8 | 0.3% | Nov 13, 2024 | Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate t... |
| CVE-2024-37376 | HIGH | 7.2 | 3.1% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-34787 | HIGH | 7.8 | 17.9% | Nov 13, 2024 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now