2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30616 | HIGH | 8.8 | 0.6% | Nov 4, 2024 | Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sens... |
| CVE-2024-51329 | HIGH | 8.8 | 0.6% | Nov 4, 2024 | A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user in... |
| CVE-2024-51326 | HIGH | 7.5 | 0.9% | Nov 4, 2024 | SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrar... |
| CVE-2024-51127 | HIGH | 7.1 | 0.7% | Nov 4, 2024 | An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensit... |
| CVE-2024-48336 | HIGH | 8.4 | 0.5% | Nov 4, 2024 | The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app b... |
| CVE-2024-48809 | HIGH | 7.5 | 0.6% | Nov 4, 2024 | An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a ... |
| CVE-2024-51626 | HIGH | 8.8 | 0.4% | Nov 4, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocom... |
| CVE-2024-45893 | HIGH | 8 | 1.6% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45891 | HIGH | 8 | 1.3% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45890 | HIGH | 8 | 2.1% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when ... |
| CVE-2024-45889 | HIGH | 8 | 1.6% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45888 | HIGH | 8 | 2.0% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parame... |
| CVE-2024-45887 | HIGH | 8 | 2.1% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45885 | HIGH | 8 | 1.3% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45884 | HIGH | 8 | 2.1% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45882 | HIGH | 8 | 1.5% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parame... |
| CVE-2024-51672 | HIGH | 7.2 | 0.5% | Nov 4, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper Better... |
| CVE-2024-51582 | HIGH | 8.8 | 0.5% | Nov 4, 2024 | Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion... |
| CVE-2024-51253 | HIGH | 8 | 0.7% | Nov 4, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51251 | HIGH | 8 | 0.7% | Nov 4, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51249 | HIGH | 8 | 0.7% | Nov 4, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51246 | HIGH | 8 | 0.4% | Nov 4, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-50530 | HIGH | 8.8 | 0.5% | Nov 4, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer al... |
| CVE-2024-50529 | HIGH | 8.8 | 0.5% | Nov 4, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a We... |
| CVE-2024-50528 | HIGH | 7.5 | 0.4% | Nov 4, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Bui... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now