2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9307 | HIGH | 8.8 | 0.9% | Nov 6, 2024 | The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up ... |
| CVE-2024-10020 | HIGH | 8.1 | 0.5% | Nov 6, 2024 | The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, an... |
| CVE-2024-49401 | HIGH | 7.1 | 0.2% | Nov 6, 2024 | Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privi... |
| CVE-2024-34679 | HIGH | 7.1 | 0.1% | Nov 6, 2024 | Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone... |
| CVE-2024-34678 | HIGH | 7.8 | 0.2% | Nov 6, 2024 | Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corrup... |
| CVE-2024-34676 | HIGH | 7.3 | 0.2% | Nov 6, 2024 | Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attacker... |
| CVE-2024-10028 | HIGH | 7.5 | 0.4% | Nov 6, 2024 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to S... |
| CVE-2024-47463 | HIGH | 7.2 | 1.2% | Nov 5, 2024 | An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful explo... |
| CVE-2024-47462 | HIGH | 7.2 | 1.2% | Nov 5, 2024 | An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful explo... |
| CVE-2024-47461 | HIGH | 7.2 | 1.7% | Nov 5, 2024 | An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A succes... |
| CVE-2024-51116 | HIGH | 8.8 | 0.4% | Nov 5, 2024 | Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'. |
| CVE-2024-7995 | HIGH | 7.8 | 0.2% | Nov 5, 2024 | A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to a... |
| CVE-2024-51740 | HIGH | 8.8 | 0.5% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests o... |
| CVE-2024-51735 | HIGH | 8.7 | 0.4% | Nov 5, 2024 | Osmedeus is a Workflow Engine for Offensive Security. Cross-site Scripting (XSS) occurs on the Osmedues web server when ... |
| CVE-2024-51382 | HIGH | 8.4 | 0.2% | Nov 5, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password... |
| CVE-2024-51381 | HIGH | 8.4 | 0.2% | Nov 5, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for ad... |
| CVE-2024-51380 | HIGH | 8.4 | 0.5% | Nov 5, 2024 | Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows... |
| CVE-2024-51379 | HIGH | 8.4 | 0.6% | Nov 5, 2024 | Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description ... |
| CVE-2024-51240 | HIGH | 8 | 0.3% | Nov 5, 2024 | An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root v... |
| CVE-2024-50333 | HIGH | 8.8 | 0.4% | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is ... |
| CVE-2024-50332 | HIGH | 8.8 | 0.4% | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient i... |
| CVE-2024-49774 | HIGH | 7.2 | 0.5% | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relie... |
| CVE-2024-49772 | HIGH | 8.8 | 0.4% | Nov 5, 2024 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM ve... |
| CVE-2024-50131 | HIGH | 7.8 | 0.2% | Nov 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: tracing: Consider the NULL character when validatin... |
| CVE-2024-50130 | HIGH | 7.8 | 0.2% | Nov 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: must hold reference on net namespac... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now