2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47080 | HIGH | 8.7 | 0.7% | Oct 15, 2024 | matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 t... |
| CVE-2024-48282 | HIGH | 7.6 | 0.4% | Oct 15, 2024 | A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Manag... |
| CVE-2024-48280 | HIGH | 7.6 | 0.4% | Oct 15, 2024 | A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Managemen... |
| CVE-2024-48279 | HIGH | 7.6 | 0.6% | Oct 15, 2024 | A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Manageme... |
| CVE-2024-9975 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by t... |
| CVE-2024-49387 | HIGH | 7.5 | 0.2% | Oct 15, 2024 | Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis ... |
| CVE-2024-45276 | HIGH | 7.5 | 0.6% | Oct 15, 2024 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. |
| CVE-2024-45273 | HIGH | 7.8 | 0.1% | Oct 15, 2024 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak ... |
| CVE-2024-45272 | HIGH | 7.5 | 0.6% | Oct 15, 2024 | An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with... |
| CVE-2024-45271 | HIGH | 7.8 | 0.3% | Oct 15, 2024 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. |
| CVE-2024-9983 | HIGH | 7.5 | 0.7% | Oct 15, 2024 | Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remo... |
| CVE-2024-9981 | HIGH | 8.8 | 0.8% | Oct 15, 2024 | The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul... |
| CVE-2024-9980 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul... |
| CVE-2024-9837 | HIGH | 7.3 | 0.6% | Oct 15, 2024 | The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution ... |
| CVE-2024-46898 | HIGH | 7.5 | 1.0% | Oct 15, 2024 | SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If t... |
| CVE-2024-0129 | HIGH | 7.8 | 0.2% | Oct 15, 2024 | NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe... |
| CVE-2024-9971 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing... |
| CVE-2024-9970 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular priv... |
| CVE-2024-9968 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to in... |
| CVE-2024-9820 | HIGH | 7.5 | 0.4% | Oct 15, 2024 | The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and i... |
| CVE-2024-9687 | HIGH | 8.8 | 0.5% | Oct 15, 2024 | The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3... |
| CVE-2024-6207 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send ... |
| CVE-2024-48911 | HIGH | 7.8 | 0.2% | Oct 14, 2024 | OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0... |
| CVE-2024-48824 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attack... |
| CVE-2024-48822 | HIGH | 8.8 | 0.5% | Oct 14, 2024 | Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now