2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10947 | HIGH | 7.2 | 0.5% | Nov 7, 2024 | A vulnerability classified as critical was found in Guangzhou Tuchuang Computer Software Development Interlib Library Cl... |
| CVE-2024-10946 | HIGH | 7.2 | 0.5% | Nov 7, 2024 | A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Libra... |
| CVE-2024-48325 | HIGH | 8.1 | 0.9% | Nov 6, 2024 | Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoC... |
| CVE-2024-50340 | HIGH | 7.3 | 63.4% | Nov 6, 2024 | symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. ... |
| CVE-2024-20536 | HIGH | 8.8 | 0.8% | Nov 6, 2024 | A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (ND... |
| CVE-2024-20528 | HIGH | 7.2 | 0.6% | Nov 6, 2024 | A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locat... |
| CVE-2024-20484 | HIGH | 7.5 | 0.6% | Nov 6, 2024 | A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could a... |
| CVE-2024-10827 | HIGH | 8.8 | 0.6% | Nov 6, 2024 | Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap ... |
| CVE-2024-10826 | HIGH | 8.8 | 0.6% | Nov 6, 2024 | Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to po... |
| CVE-2024-6861 | HIGH | 7.5 | 0.7% | Nov 6, 2024 | A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is ena... |
| CVE-2024-8614 | HIGH | 8.8 | 0.8% | Nov 6, 2024 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2024-9946 | HIGH | 8.1 | 0.6% | Nov 6, 2024 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authe... |
| CVE-2024-9307 | HIGH | 8.8 | 0.9% | Nov 6, 2024 | The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up ... |
| CVE-2024-10020 | HIGH | 8.1 | 0.5% | Nov 6, 2024 | The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, an... |
| CVE-2024-49401 | HIGH | 7.1 | 0.2% | Nov 6, 2024 | Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privi... |
| CVE-2024-34679 | HIGH | 7.1 | 0.1% | Nov 6, 2024 | Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone... |
| CVE-2024-34678 | HIGH | 7.8 | 0.2% | Nov 6, 2024 | Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corrup... |
| CVE-2024-34676 | HIGH | 7.3 | 0.2% | Nov 6, 2024 | Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attacker... |
| CVE-2024-10028 | HIGH | 7.5 | 0.4% | Nov 6, 2024 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to S... |
| CVE-2024-47463 | HIGH | 7.2 | 1.2% | Nov 5, 2024 | An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful explo... |
| CVE-2024-47462 | HIGH | 7.2 | 1.2% | Nov 5, 2024 | An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful explo... |
| CVE-2024-47461 | HIGH | 7.2 | 1.7% | Nov 5, 2024 | An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A succes... |
| CVE-2024-51116 | HIGH | 8.8 | 0.4% | Nov 5, 2024 | Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'. |
| CVE-2024-7995 | HIGH | 7.8 | 0.2% | Nov 5, 2024 | A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to a... |
| CVE-2024-51740 | HIGH | 8.8 | 0.5% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now