2024 CVE Vulnerabilities
39,220 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43162 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Se... |
| CVE-2024-43158 | HIGH | 7.5 | 0.5% | Nov 1, 2024 | Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo... |
| CVE-2024-43142 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in Themeum Tutor LMS allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2024-43136 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Suns... |
| CVE-2024-43118 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance... |
| CVE-2024-39664 | HIGH | 7.3 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in YMC Filter & Grids allows Accessing Functionality Not Properly Constrained by ACL... |
| CVE-2024-39635 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in KaineLabs Youzify allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2024-38744 | HIGH | 8.3 | 0.3% | Nov 1, 2024 | Missing Authorization vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows Accessing Functionality Not Properl... |
| CVE-2024-38726 | HIGH | 7.5 | 0.5% | Nov 1, 2024 | Missing Authorization vulnerability in PickPlugins Product Designer allows Accessing Functionality Not Properly Constrai... |
| CVE-2024-38721 | HIGH | 7.1 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Se... |
| CVE-2024-38707 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Se... |
| CVE-2024-37517 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2024-37453 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Ac... |
| CVE-2024-37423 | HIGH | 8.5 | 0.4% | Nov 1, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Bloc... |
| CVE-2024-37232 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in Hercules Design Hercules Core allows Exploiting Incorrectly Configured Access Con... |
| CVE-2024-37108 | HIGH | 7.7 | 0.6% | Nov 1, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WishList Products WishLi... |
| CVE-2024-37106 | HIGH | 8.2 | 0.3% | Nov 1, 2024 | Missing Authorization vulnerability in WishList Products WishList Member X allows Exploiting Incorrectly Configured Acce... |
| CVE-2024-27524 | HIGH | 7.1 | 0.7% | Nov 1, 2024 | Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafte... |
| CVE-2024-48270 | HIGH | 7.5 | 0.5% | Nov 1, 2024 | An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack. |
| CVE-2024-10653 | HIGH | 7.2 | 0.6% | Nov 1, 2024 | IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator inter... |
| CVE-2024-0106 | HIGH | 8.7 | 0.2% | Nov 1, 2024 | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker ma... |
| CVE-2024-0105 | HIGH | 8.9 | 0.3% | Nov 1, 2024 | NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privi... |
| CVE-2024-47939 | HIGH | 7.7 | 0.7% | Nov 1, 2024 | Stack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Mon... |
| CVE-2024-10613 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the fun... |
| CVE-2024-10612 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function removeHookInva... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now