2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49522 | HIGH | 7.8 | 0.3% | Nov 5, 2024 | Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result... |
| CVE-2024-52022 | HIGH | 8 | 1.0% | Nov 5, 2024 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a comman... |
| CVE-2024-52021 | HIGH | 8 | 1.0% | Nov 5, 2024 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw... |
| CVE-2024-52020 | HIGH | 8 | 1.0% | Nov 5, 2024 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz... |
| CVE-2024-52019 | HIGH | 8 | 1.6% | Nov 5, 2024 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at gen... |
| CVE-2024-52018 | HIGH | 8 | 1.6% | Nov 5, 2024 | Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at geni... |
| CVE-2024-51024 | HIGH | 8 | 1.4% | Nov 5, 2024 | D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the S... |
| CVE-2024-51023 | HIGH | 8.8 | 1.4% | Nov 5, 2024 | D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the Se... |
| CVE-2024-51021 | HIGH | 8 | 0.8% | Nov 5, 2024 | Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a command injection vulnera... |
| CVE-2024-51010 | HIGH | 8 | 0.9% | Nov 5, 2024 | Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a comman... |
| CVE-2024-51009 | HIGH | 8 | 0.9% | Nov 5, 2024 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at eth... |
| CVE-2024-51008 | HIGH | 8 | 0.9% | Nov 5, 2024 | Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_... |
| CVE-2024-51005 | HIGH | 8 | 0.8% | Nov 5, 2024 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_... |
| CVE-2024-50993 | HIGH | 8 | 0.9% | Nov 5, 2024 | Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at ad... |
| CVE-2024-10841 | HIGH | 8 | 0.4% | Nov 5, 2024 | A vulnerability classified as critical was found in romadebrian WEB-Sekolah 1.0. Affected by this vulnerability is an un... |
| CVE-2024-7059 | HIGH | 8.9 | 0.5% | Nov 5, 2024 | A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found... |
| CVE-2024-10263 | HIGH | 7.3 | 0.5% | Nov 5, 2024 | The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versi... |
| CVE-2024-51523 | HIGH | 7.5 | 0.2% | Nov 5, 2024 | Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may aff... |
| CVE-2024-51518 | HIGH | 7.5 | 0.3% | Nov 5, 2024 | Vulnerability of message types not being verified in the advanced messaging modul Impact: Successful exploitation of thi... |
| CVE-2024-47255 | HIGH | 7.8 | 0.1% | Nov 5, 2024 | In 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which co... |
| CVE-2024-47254 | HIGH | 7.2 | 0.3% | Nov 5, 2024 | In 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability coul... |
| CVE-2024-47253 | HIGH | 7.2 | 0.9% | Nov 5, 2024 | In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administr... |
| CVE-2024-10711 | HIGH | 8.8 | 0.3% | Nov 5, 2024 | The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-10114 | HIGH | 8.1 | 0.5% | Nov 5, 2024 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and in... |
| CVE-2024-47797 | HIGH | 7.8 | 0.2% | Nov 5, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now