2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50359 | HIGH | 7.2 | 1.4% | Nov 26, 2024 | A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff... |
| CVE-2024-50358 | HIGH | 7.2 | 0.5% | Nov 26, 2024 | A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactur... |
| CVE-2024-11024 | CRITICAL | 9.8 | 0.7% | Nov 26, 2024 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in... |
| CVE-2024-10579 | MEDIUM | 4.3 | 0.4% | Nov 26, 2024 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access ... |
| CVE-2024-10308 | MEDIUM | 5.4 | 0.3% | Nov 26, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdow... |
| CVE-2024-11680 | CRITICAL | 9.8 | 91.6% | Nov 26, 2024 | ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated at... |
| CVE-2024-11032 | MEDIUM | 6.1 | 0.4% | Nov 26, 2024 | The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg with... |
| CVE-2024-9170 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_produ... |
| CVE-2024-11192 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2024-11119 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' sh... |
| CVE-2024-11091 | MEDIUM | 6.4 | 0.4% | Nov 26, 2024 | The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-9504 | HIGH | 7.2 | 0.5% | Nov 26, 2024 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via S... |
| CVE-2024-8772 | MEDIUM | 4.3 | 0.4% | Nov 26, 2024 | 51l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable ... |
| CVE-2024-8160 | LOW | 2.7 | 0.6% | Nov 26, 2024 | Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficie... |
| CVE-2024-6831 | MEDIUM | 4.4 | 0.2% | Nov 26, 2024 | Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove vie... |
| CVE-2024-47257 | HIGH | 7.5 | 0.5% | Nov 26, 2024 | Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead... |
| CVE-2024-36254 | HIGH | 7.5 | 0.7% | Nov 26, 2024 | Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction pr... |
| CVE-2024-36251 | HIGH | 7.5 | 3.5% | Nov 26, 2024 | The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More... |
| CVE-2024-36249 | HIGH | 7.4 | 0.5% | Nov 26, 2024 | Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction... |
| CVE-2024-36248 | CRITICAL | 9.1 | 1.1% | Nov 26, 2024 | API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model... |
| CVE-2024-35244 | CRITICAL | 9.1 | 1.1% | Nov 26, 2024 | There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their ... |
| CVE-2024-34162 | MEDIUM | 5.3 | 0.8% | Nov 26, 2024 | The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But co... |
| CVE-2024-33616 | MEDIUM | 5.3 | 0.9% | Nov 26, 2024 | Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrat... |
| CVE-2024-33610 | CRITICAL | 9.1 | 45.1% | Nov 26, 2024 | "sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides log... |
| CVE-2024-33605 | HIGH | 7.5 | 6.2% | Nov 26, 2024 | Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for th... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now