2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46054 | CRITICAL | 9.8 | 0.8% | Nov 27, 2024 | OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, all... |
| CVE-2024-11862 | MEDIUM | 5.1 | 0.1% | Nov 27, 2024 | Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render hal... |
| CVE-2024-53635 | MEDIUM | 4.8 | 0.5% | Nov 27, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COV... |
| CVE-2024-53604 | CRITICAL | 9.8 | 1.0% | Nov 27, 2024 | A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management S... |
| CVE-2024-53603 | HIGH | 7.3 | 0.7% | Nov 27, 2024 | A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management Sy... |
| CVE-2024-36464 | LOW | 2.7 | 0.5% | Nov 27, 2024 | When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type... |
| CVE-2024-42333 | LOW | 2.7 | 0.6% | Nov 27, 2024 | The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read... |
| CVE-2024-42332 | LOW | 3.7 | 0.6% | Nov 27, 2024 | The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with addit... |
| CVE-2024-42331 | LOW | 3.3 | 0.3% | Nov 27, 2024 | In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript... |
| CVE-2024-42330 | CRITICAL | 9.1 | 1.0% | Nov 27, 2024 | The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem ... |
| CVE-2024-42329 | LOW | 3.3 | 0.2% | Nov 27, 2024 | The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function... |
| CVE-2024-42328 | MEDIUM | 5.5 | 0.2% | Nov 27, 2024 | When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allo... |
| CVE-2024-42327 | CRITICAL | 9.9 | 78.8% | Nov 27, 2024 | A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access... |
| CVE-2024-42326 | MEDIUM | 4.4 | 0.2% | Nov 27, 2024 | There was discovered a use after free bug in browser.c in the es_browser_get_variant function |
| CVE-2024-36468 | HIGH | 8.2 | 0.5% | Nov 27, 2024 | The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix s... |
| CVE-2024-11009 | MEDIUM | 4.9 | 0.4% | Nov 27, 2024 | The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable... |
| CVE-2024-11025 | MEDIUM | 5.4 | 0.2% | Nov 27, 2024 | An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administrat... |
| CVE-2024-10521 | MEDIUM | 4.3 | 0.2% | Nov 27, 2024 | The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ... |
| CVE-2024-52323 | HIGH | 8.1 | 1.1% | Nov 27, 2024 | Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which a... |
| CVE-2024-11667 | CRITICAL | 9.8 | 3.0% | Nov 27, 2024 | A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through ... |
| CVE-2024-36467 | HIGH | 8.8 | 0.7% | Nov 27, 2024 | An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the u... |
| CVE-2024-10895 | MEDIUM | 6.4 | 0.2% | Nov 27, 2024 | The Counter Up – Animated Number Counter & Milestone Showcase plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-10580 | MEDIUM | 5.3 | 0.4% | Nov 27, 2024 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form su... |
| CVE-2024-10175 | MEDIUM | 6.4 | 0.3% | Nov 27, 2024 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2024-52959 | HIGH | 7.2 | 0.6% | Nov 27, 2024 | A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversation... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now