2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42011 | HIGH | 7.5 | 0.6% | Oct 28, 2024 | The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat. |
| CVE-2024-50457 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50453 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusi... |
| CVE-2024-50436 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50435 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50434 | HIGH | 8.8 | 0.4% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-48826 | HIGH | 8.8 | 1.7% | Oct 28, 2024 | Tenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arb... |
| CVE-2024-48825 | HIGH | 8.8 | 1.7% | Oct 28, 2024 | Tenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute a... |
| CVE-2024-48196 | HIGH | 7.5 | 0.5% | Oct 28, 2024 | An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post pa... |
| CVE-2024-48178 | HIGH | 8.1 | 0.3% | Oct 28, 2024 | newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter. |
| CVE-2024-6245 | HIGH | 7.4 | 0.2% | Oct 28, 2024 | Use of Default Credentials vulnerability in Maruti Suzuki SmartPlay on Linux (Infotainment Hub modules) allows attacker ... |
| CVE-2024-42028 | HIGH | 8.8 | 0.2% | Oct 28, 2024 | A Local privilege escalation vulnerability found in a Self-Hosted UniFi Network Server with UniFi Network Application (V... |
| CVE-2024-49761 | HIGH | 7.5 | 1.4% | Oct 28, 2024 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has ma... |
| CVE-2024-45802 | HIGH | 7.5 | 45.3% | Oct 28, 2024 | Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premat... |
| CVE-2024-10455 | HIGH | 7.5 | 0.4% | Oct 28, 2024 | Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block |
| CVE-2024-50574 | HIGH | 7.5 | 0.6% | Oct 28, 2024 | In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk func... |
| CVE-2024-50488 | HIGH | 8.8 | 0.9% | Oct 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authenti... |
| CVE-2024-10447 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vul... |
| CVE-2024-50442 | HIGH | 7.2 | 0.5% | Oct 28, 2024 | Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-a... |
| CVE-2024-50416 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer ... |
| CVE-2024-50408 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affec... |
| CVE-2024-48074 | HIGH | 8 | 0.7% | Oct 28, 2024 | An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a mali... |
| CVE-2024-10446 | HIGH | 7.2 | 0.5% | Oct 28, 2024 | A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an ... |
| CVE-2024-9162 | HIGH | 7.2 | 2.7% | Oct 28, 2024 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing... |
| CVE-2024-10439 | HIGH | 7.5 | 0.4% | Oct 28, 2024 | The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now