2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8936 | HIGH | 8.3 | 0.5% | Nov 13, 2024 | CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory a... |
| CVE-2024-8935 | HIGH | 7.7 | 0.5% | Nov 13, 2024 | CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confide... |
| CVE-2024-10800 | HIGH | 8.8 | 0.8% | Nov 13, 2024 | The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability c... |
| CVE-2024-8933 | HIGH | 7.5 | 0.3% | Nov 13, 2024 | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t... |
| CVE-2024-10816 | HIGH | 7.5 | 1.1% | Nov 13, 2024 | The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.... |
| CVE-2024-10174 | HIGH | 7.3 | 0.6% | Nov 13, 2024 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo... |
| CVE-2024-39709 | HIGH | 7.8 | 0.3% | Nov 13, 2024 | Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Se... |
| CVE-2024-38655 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version... |
| CVE-2024-38649 | HIGH | 7.5 | 1.9% | Nov 13, 2024 | An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remot... |
| CVE-2024-37400 | HIGH | 7.5 | 2.0% | Nov 13, 2024 | An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigg... |
| CVE-2024-37398 | HIGH | 7.8 | 0.3% | Nov 13, 2024 | Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate t... |
| CVE-2024-37376 | HIGH | 7.2 | 3.1% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-34787 | HIGH | 7.8 | 17.9% | Nov 13, 2024 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo... |
| CVE-2024-34784 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-34782 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-34781 | HIGH | 7.2 | 67.7% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-34780 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-32847 | HIGH | 7.2 | 3.1% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-32844 | HIGH | 7.2 | 1.7% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-32841 | HIGH | 7.2 | 3.3% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-32839 | HIGH | 7.2 | 3.3% | Nov 13, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-10629 | HIGH | 8.8 | 1.6% | Nov 13, 2024 | The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file ... |
| CVE-2024-28726 | HIGH | 8 | 8.1% | Nov 12, 2024 | An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to e... |
| CVE-2024-51179 | HIGH | 7.5 | 1.0% | Nov 12, 2024 | An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizati... |
| CVE-2024-51094 | HIGH | 8 | 0.4% | Nov 12, 2024 | An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a mal... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now