2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51254 | HIGH | 8.8 | 0.4% | Oct 31, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-49685 | HIGH | 8.8 | 0.2% | Oct 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds... |
| CVE-2024-43984 | HIGH | 8.8 | 0.3% | Oct 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue af... |
| CVE-2024-43383 | HIGH | 8.1 | 1.2% | Oct 31, 2024 | Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's... |
| CVE-2024-21537 | HIGH | 8.9 | 1.1% | Oct 31, 2024 | Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the inse... |
| CVE-2024-48311 | HIGH | 8.8 | 0.3% | Oct 31, 2024 | Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function. |
| CVE-2024-10559 | HIGH | 7.8 | 0.4% | Oct 31, 2024 | A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected b... |
| CVE-2024-51426 | HIGH | 8.8 | 0.5% | Oct 30, 2024 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an... |
| CVE-2024-51425 | HIGH | 8.8 | 0.4% | Oct 30, 2024 | An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have ... |
| CVE-2024-51243 | HIGH | 7.2 | 0.9% | Oct 30, 2024 | The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deploy... |
| CVE-2024-48735 | HIGH | 7.7 | 1.0% | Oct 30, 2024 | Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote ... |
| CVE-2024-48734 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote atta... |
| CVE-2024-48733 | HIGH | 8.8 | 0.7% | Oct 30, 2024 | SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to e... |
| CVE-2024-48093 | HIGH | 8 | 0.6% | Oct 30, 2024 | Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Exe... |
| CVE-2024-48271 | HIGH | 8.8 | 0.9% | Oct 30, 2024 | D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly ... |
| CVE-2024-48647 | HIGH | 7.2 | 0.8% | Oct 30, 2024 | A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbit... |
| CVE-2024-48646 | HIGH | 8.1 | 0.5% | Oct 30, 2024 | An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files with... |
| CVE-2024-48214 | HIGH | 8.4 | 1.0% | Oct 30, 2024 | KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local netw... |
| CVE-2024-42041 | HIGH | 8.1 | 0.3% | Oct 30, 2024 | The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 f... |
| CVE-2024-37573 | HIGH | 8.4 | 0.2% | Oct 30, 2024 | The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions... |
| CVE-2024-36060 | HIGH | 8.8 | 1.4% | Oct 30, 2024 | EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping ... |
| CVE-2024-51258 | HIGH | 8.8 | 0.5% | Oct 30, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-51301 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51300 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51299 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now