2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45261 | HIGH | 8 | 0.5% | Oct 24, 2024 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID... |
| CVE-2024-45260 | HIGH | 8 | 3.9% | Oct 24, 2024 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users w... |
| CVE-2024-10327 | HIGH | 8.1 | 0.6% | Oct 24, 2024 | A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification respo... |
| CVE-2024-45242 | HIGH | 7.8 | 34.7% | Oct 24, 2024 | EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metachar... |
| CVE-2024-48454 | HIGH | 7.2 | 0.9% | Oct 24, 2024 | An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via ... |
| CVE-2024-48427 | HIGH | 8.8 | 0.9% | Oct 24, 2024 | A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated us... |
| CVE-2024-48142 | HIGH | 7.5 | 0.4% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows at... |
| CVE-2024-48141 | HIGH | 7.5 | 0.4% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate a... |
| CVE-2024-48140 | HIGH | 7.5 | 0.4% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v... |
| CVE-2024-48139 | HIGH | 7.5 | 0.5% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all pre... |
| CVE-2024-48441 | HIGH | 8.8 | 1.6% | Oct 24, 2024 | Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain... |
| CVE-2024-48440 | HIGH | 8.8 | 1.6% | Oct 24, 2024 | Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered t... |
| CVE-2024-10338 | HIGH | 7.2 | 0.4% | Oct 24, 2024 | A vulnerability classified as critical was found in SourceCodeHero Clothes Recommendation System 1.0. Affected by this v... |
| CVE-2024-10337 | HIGH | 7.2 | 0.4% | Oct 24, 2024 | A vulnerability classified as critical has been found in SourceCodeHero Clothes Recommendation System 1.0. Affected is a... |
| CVE-2024-10313 | HIGH | 8.6 | 0.5% | Oct 24, 2024 | iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malici... |
| CVE-2024-10295 | HIGH | 7.5 | 0.4% | Oct 24, 2024 | A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly ... |
| CVE-2024-48547 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to a... |
| CVE-2024-48546 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access se... |
| CVE-2024-48545 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access se... |
| CVE-2024-48544 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to... |
| CVE-2024-48542 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows att... |
| CVE-2024-48541 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to acces... |
| CVE-2024-5608 | HIGH | 8.1 | 1.3% | Oct 24, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature... |
| CVE-2024-49691 | HIGH | 7.6 | 0.4% | Oct 24, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Produc... |
| CVE-2024-10331 | HIGH | 8.8 | 0.5% | Oct 24, 2024 | A vulnerability, which was classified as critical, has been found in PHPGurukul Vehicle Record System 1.0. This issue af... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now