2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51602 | HIGH | 8.5 | 0.4% | Nov 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in oleksandr87 Simple... |
| CVE-2024-51601 | HIGH | 8.5 | 0.4% | Nov 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Maksym Marko Websi... |
| CVE-2024-51579 | HIGH | 8.5 | 0.4% | Nov 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team: ... |
| CVE-2024-51570 | HIGH | 8.5 | 0.4% | Nov 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in odihost Easy Galle... |
| CVE-2024-9874 | HIGH | 7.2 | 0.7% | Nov 9, 2024 | The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injecti... |
| CVE-2024-10674 | HIGH | 8.8 | 1.7% | Nov 9, 2024 | The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capab... |
| CVE-2024-10673 | HIGH | 8.8 | 1.1% | Nov 9, 2024 | The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capabilit... |
| CVE-2024-10626 | HIGH | 8.1 | 0.9% | Nov 9, 2024 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient ... |
| CVE-2024-10294 | HIGH | 7.5 | 0.3% | Nov 9, 2024 | The CE21 Suite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-10285 | HIGH | 7.5 | 0.6% | Nov 9, 2024 | The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the plugin-log.txt in versions... |
| CVE-2024-52007 | HIGH | 8.6 | 0.9% | Nov 8, 2024 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing pe... |
| CVE-2024-52004 | HIGH | 8.7 | 0.7% | Nov 8, 2024 | MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has b... |
| CVE-2024-52002 | HIGH | 8.8 | 0.6% | Nov 8, 2024 | Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Reques... |
| CVE-2024-35423 | HIGH | 7.8 | 0.3% | Nov 8, 2024 | vmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_w... |
| CVE-2024-35422 | HIGH | 7.8 | 0.3% | Nov 8, 2024 | vmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c. |
| CVE-2024-27532 | HIGH | 7.5 | 0.5% | Nov 8, 2024 | wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function... |
| CVE-2024-27530 | HIGH | 8.4 | 0.2% | Nov 8, 2024 | wasm3 139076a contains a Use-After-Free in ForEachModule. |
| CVE-2024-27529 | HIGH | 8.4 | 0.3% | Nov 8, 2024 | wasm3 139076a contains memory leaks in Read_utf8. |
| CVE-2024-27528 | HIGH | 8.4 | 0.2% | Nov 8, 2024 | wasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution. |
| CVE-2024-27527 | HIGH | 7.5 | 0.4% | Nov 8, 2024 | wasm3 139076a is vulnerable to Denial of Service (DoS). |
| CVE-2024-11026 | HIGH | 7.4 | 0.6% | Nov 8, 2024 | A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated as problematic. Affected... |
| CVE-2024-50809 | HIGH | 8.8 | 0.7% | Nov 8, 2024 | The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands |
| CVE-2024-50808 | HIGH | 8.8 | 0.6% | Nov 8, 2024 | SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the ... |
| CVE-2024-51997 | HIGH | 8.1 | 0.3% | Nov 8, 2024 | Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Att... |
| CVE-2024-51152 | HIGH | 7.2 | 0.9% | Nov 8, 2024 | File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbitrary code via the s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now