2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48448 | MEDIUM | 6.1 | 0.3% | Oct 25, 2024 | An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploadin... |
| CVE-2024-48343 | MEDIUM | 6.3 | 0.4% | Oct 25, 2024 | A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id para... |
| CVE-2024-8036 | MEDIUM | 5.9 | 0.1% | Oct 25, 2024 | ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exp... |
| CVE-2024-48743 | MEDIUM | 6.5 | 0.4% | Oct 25, 2024 | Cross Site Scripting vulnerability in Sentry v.6.0.9 allows a remote attacker to execute arbitrary code via the z parame... |
| CVE-2024-48654 | MEDIUM | 6.1 | 0.4% | Oct 25, 2024 | Cross Site Scripting vulnerability in Blood Bank v.1 allows a remote attacker to execute arbitrary code via a crafted sc... |
| CVE-2024-49757 | MEDIUM | 4.9 | 2.6% | Oct 25, 2024 | The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Du... |
| CVE-2024-49378 | MEDIUM | 6.1 | 0.3% | Oct 25, 2024 | smartUp, a web browser mouse gestures extension, has a universal cross-site scripting issue in the Edge and Firefox vers... |
| CVE-2024-10374 | MEDIUM | 5.4 | 0.4% | Oct 25, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpme... |
| CVE-2024-47483 | MEDIUM | 5.5 | 0.2% | Oct 25, 2024 | Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in a... |
| CVE-2024-47481 | MEDIUM | 6.5 | 0.2% | Oct 25, 2024 | Dell Data Lakehouse, version(s) 1.0.0.0, 1.1.0., contain(s) an Improper Access Control vulnerability. An unauthenticated... |
| CVE-2024-47034 | MEDIUM | 5.5 | 0.1% | Oct 25, 2024 | there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure wi... |
| CVE-2024-47030 | MEDIUM | 5.1 | 0.1% | Oct 25, 2024 | Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-315191818. |
| CVE-2024-47029 | MEDIUM | 5.5 | 0.1% | Oct 25, 2024 | In TrustySharedMemoryManager::GetSharedMemory of ondevice/trusty/trusty_shared_memory_manager.cc, there is a possible ou... |
| CVE-2024-47028 | MEDIUM | 4.4 | 0.1% | Oct 25, 2024 | In ffu_flash_pack of ffu.c, there is a possible out of bounds read due to an integer overflow. This could lead to local ... |
| CVE-2024-47026 | MEDIUM | 5.5 | 0.1% | Oct 25, 2024 | In gsc_gsa_rescue of gsc_gsa.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead... |
| CVE-2024-47025 | MEDIUM | 5.5 | 0.1% | Oct 25, 2024 | In ppmp_protect_buf of drm_fw.c, there is a possible information disclosure due to a logic error in the code. This could... |
| CVE-2024-47019 | MEDIUM | 5.5 | 0.1% | Oct 25, 2024 | In ProtocolEmbmsSaiListAdapter::Init() of protocolembmsadapter.cpp, there is a possible out of bounds read due to a miss... |
| CVE-2024-47018 | MEDIUM | 5.5 | 0.1% | Oct 25, 2024 | In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible out of bounds read due to a buffer overflow. This... |
| CVE-2024-47015 | MEDIUM | 5.5 | 0.1% | Oct 25, 2024 | In ProtocolMiscHwConfigChangeAdapter::GetData() of protocolmiscadapter.cpp, there is a possible out-of-bounds read due t... |
| CVE-2024-44099 | MEDIUM | 5.5 | 0.1% | Oct 25, 2024 | There is a possible Local bypass of user interaction due to an insecure default value. This could lead to local informat... |
| CVE-2024-8666 | MEDIUM | 6.4 | 0.3% | Oct 25, 2024 | The Shoutcast Icecast HTML5 Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-10343 | MEDIUM | 6.4 | 0.3% | Oct 25, 2024 | The Beek Widget Extention plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions u... |
| CVE-2024-10112 | MEDIUM | 6.4 | 0.3% | Oct 25, 2024 | The Simple News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'news' shortcode in a... |
| CVE-2024-10016 | MEDIUM | 6.4 | 0.4% | Oct 25, 2024 | The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ... |
| CVE-2024-9630 | MEDIUM | 5.3 | 0.3% | Oct 25, 2024 | The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now