2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53701 | LOW | 3.1 | 0.2% | Nov 29, 2024 | Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications... |
| CVE-2024-39162 | MEDIUM | 6.1 | 0.4% | Nov 29, 2024 | pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported ... |
| CVE-2024-11980 | HIGH | 8.6 | 0.5% | Nov 29, 2024 | Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated rem... |
| CVE-2024-10980 | MEDIUM | 5.4 | 0.3% | Nov 29, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress ... |
| CVE-2024-10704 | MEDIUM | 4.8 | 0.4% | Nov 29, 2024 | The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-48651 | HIGH | 7.5 | 2.2% | Nov 29, 2024 | In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th... |
| CVE-2024-45495 | MEDIUM | 4.3 | 0.2% | Nov 29, 2024 | MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking. |
| CVE-2024-35451 | MEDIUM | 4.8 | 0.3% | Nov 29, 2024 | LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF. |
| CVE-2024-54124 | HIGH | 8.8 | 0.4% | Nov 29, 2024 | In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen. |
| CVE-2024-54123 | MEDIUM | 6.1 | 0.3% | Nov 29, 2024 | Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text... |
| CVE-2024-11979 | CRITICAL | 9.8 | 0.8% | Nov 29, 2024 | DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This all... |
| CVE-2024-11978 | HIGH | 7.5 | 0.7% | Nov 29, 2024 | DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this ... |
| CVE-2024-9852 | HIGH | 7.8 | 0.2% | Nov 28, 2024 | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E... |
| CVE-2024-8300 | HIGH | 7 | 0.2% | Nov 28, 2024 | Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsub... |
| CVE-2024-8299 | HIGH | 7.8 | 0.2% | Nov 28, 2024 | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E... |
| CVE-2024-11971 | MEDIUM | 5.4 | 0.5% | Nov 28, 2024 | A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerab... |
| CVE-2024-11970 | CRITICAL | 9.8 | 0.8% | Nov 28, 2024 | A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is a... |
| CVE-2024-11968 | HIGH | 7.5 | 0.5% | Nov 28, 2024 | A vulnerability was found in code-projects Farmacia up to 1.0. It has been declared as critical. Affected by this vulner... |
| CVE-2024-11967 | CRITICAL | 9.8 | 0.7% | Nov 28, 2024 | A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is... |
| CVE-2024-11966 | CRITICAL | 9.8 | 0.8% | Nov 28, 2024 | A vulnerability was found in PHPGurukul Complaint Management system 1.0 and classified as critical. This issue affects s... |
| CVE-2024-52338 | CRITICAL | 9.8 | 2.3% | Nov 28, 2024 | Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0... |
| CVE-2024-11965 | CRITICAL | 9.8 | 0.8% | Nov 28, 2024 | A vulnerability has been found in PHPGurukul Complaint Management system 1.0 and classified as critical. This vulnerabil... |
| CVE-2024-11964 | CRITICAL | 9.8 | 0.8% | Nov 28, 2024 | A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management system 1.0. This affects... |
| CVE-2024-11969 | HIGH | 8.8 | 0.2% | Nov 28, 2024 | The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerabili... |
| CVE-2024-11963 | HIGH | 8.8 | 0.6% | Nov 28, 2024 | A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected b... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now