2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51492 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files upl... |
| CVE-2024-51248 | HIGH | 8.8 | 0.8% | Nov 1, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51247 | HIGH | 8.8 | 0.8% | Nov 1, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51245 | HIGH | 8.8 | 0.8% | Nov 1, 2024 | In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51244 | HIGH | 8.8 | 0.8% | Nov 1, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-49770 | HIGH | 7.7 | 0.7% | Nov 1, 2024 | `oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers a... |
| CVE-2024-48352 | HIGH | 7.5 | 0.5% | Nov 1, 2024 | Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTT... |
| CVE-2024-48217 | HIGH | 8.8 | 0.7% | Nov 1, 2024 | An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-p... |
| CVE-2024-41744 | HIGH | 8.8 | 0.2% | Nov 1, 2024 | IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious... |
| CVE-2024-40490 | HIGH | 7.5 | 0.5% | Nov 1, 2024 | An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX cal... |
| CVE-2024-22733 | HIGH | 7.5 | 0.6% | Nov 1, 2024 | TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration ... |
| CVE-2024-10662 | HIGH | 8.8 | 1.2% | Nov 1, 2024 | A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetD... |
| CVE-2024-10661 | HIGH | 8.8 | 1.1% | Nov 1, 2024 | A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the func... |
| CVE-2024-49256 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Incorrect Authorization vulnerability in WP Chill Htaccess File Editor htaccess-file-editor allows Accessing Functionali... |
| CVE-2024-48045 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons allows Exploiting ... |
| CVE-2024-48044 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in ShortPixel ShortPixel Image Optimizer shortpixel-image-optimiser allows Exploitin... |
| CVE-2024-48039 | HIGH | 8.8 | 0.3% | Nov 1, 2024 | Missing Authorization vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Exploiting Incorrectly Configured Ac... |
| CVE-2024-47362 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials.This issue affects Strong Testim... |
| CVE-2024-47361 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This i... |
| CVE-2024-47318 | HIGH | 8.8 | 0.3% | Nov 1, 2024 | Missing Authorization vulnerability in Magazine3 PWA for WP & AMP pwa-for-wp.This issue affects PWA for WP & AMP: from n... |
| CVE-2024-47317 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded.This issue affects Ads by WP... |
| CVE-2024-47314 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incor... |
| CVE-2024-44052 | HIGH | 8.8 | 0.3% | Nov 1, 2024 | Missing Authorization vulnerability in HelloAsso HelloAsso helloasso.This issue affects HelloAsso: from n/a through <= 1... |
| CVE-2024-44031 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in beardev JoomSport joomsport-sports-league-results-management.This issue affects J... |
| CVE-2024-44021 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in truepushplugin Truepush truepush-free-web-push-notifications.This issue affects T... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now