2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9981 | HIGH | 8.8 | 0.8% | Oct 15, 2024 | The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul... |
| CVE-2024-9980 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regul... |
| CVE-2024-9837 | HIGH | 7.3 | 0.6% | Oct 15, 2024 | The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution ... |
| CVE-2024-46898 | HIGH | 7.5 | 1.0% | Oct 15, 2024 | SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If t... |
| CVE-2024-0129 | HIGH | 7.8 | 0.2% | Oct 15, 2024 | NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe... |
| CVE-2024-9971 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing... |
| CVE-2024-9970 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular priv... |
| CVE-2024-9968 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to in... |
| CVE-2024-9820 | HIGH | 7.5 | 0.4% | Oct 15, 2024 | The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and i... |
| CVE-2024-9687 | HIGH | 8.8 | 0.5% | Oct 15, 2024 | The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3... |
| CVE-2024-6207 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send ... |
| CVE-2024-48911 | HIGH | 7.8 | 0.2% | Oct 14, 2024 | OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0... |
| CVE-2024-48824 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attack... |
| CVE-2024-48822 | HIGH | 8.8 | 0.5% | Oct 14, 2024 | Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r... |
| CVE-2024-48792 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update p... |
| CVE-2024-48791 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive informati... |
| CVE-2024-48789 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via th... |
| CVE-2024-47831 | HIGH | 7.5 | 0.7% | Oct 14, 2024 | Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.... |
| CVE-2024-48799 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information... |
| CVE-2024-48798 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive inform... |
| CVE-2024-48797 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive in... |
| CVE-2024-48796 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update ... |
| CVE-2024-45733 | HIGH | 8.8 | 1.1% | Oct 14, 2024 | In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or... |
| CVE-2024-45731 | HIGH | 8 | 0.5% | Oct 14, 2024 | In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "a... |
| CVE-2024-9823 | HIGH | 7.5 | 0.9% | Oct 14, 2024 | There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now