2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53912 | CRITICAL | 9.8 | 0.9% | Nov 24, 2024 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers... |
| CVE-2024-53911 | CRITICAL | 9.8 | 0.9% | Nov 24, 2024 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers... |
| CVE-2024-53910 | CRITICAL | 9.8 | 0.9% | Nov 24, 2024 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers... |
| CVE-2024-53909 | CRITICAL | 9.8 | 0.9% | Nov 24, 2024 | An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers... |
| CVE-2024-53901 | MEDIUM | 5.5 | 0.4% | Nov 24, 2024 | The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unsp... |
| CVE-2024-53899 | HIGH | 7.8 | 1.6% | Nov 24, 2024 | virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic templ... |
| CVE-2024-11233 | HIGH | 8.2 | 1.6% | Nov 24, 2024 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printab... |
| CVE-2024-11236 | CRITICAL | 9.8 | 2.1% | Nov 24, 2024 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_e... |
| CVE-2024-11234 | HIGH | 7.2 | 1.1% | Nov 24, 2024 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy ... |
| CVE-2024-35160 | MEDIUM | 6.5 | 0.4% | Nov 23, 2024 | IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7... |
| CVE-2024-11632 | CRITICAL | 9.8 | 0.8% | Nov 23, 2024 | A vulnerability was found in code-projects Simple Car Rental System 1.0. It has been classified as critical. Affected is... |
| CVE-2024-11631 | CRITICAL | 9.8 | 0.7% | Nov 23, 2024 | A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects... |
| CVE-2024-11231 | MEDIUM | 6.4 | 0.4% | Nov 23, 2024 | The 우커머스 네이버페이 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mnp_purchase shortcode... |
| CVE-2024-11229 | MEDIUM | 6.4 | 0.5% | Nov 23, 2024 | The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_friends and add... |
| CVE-2024-11228 | MEDIUM | 6.4 | 0.4% | Nov 23, 2024 | The 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pafw... |
| CVE-2024-11034 | HIGH | 7.3 | 0.7% | Nov 23, 2024 | The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotat... |
| CVE-2024-11227 | MEDIUM | 6.4 | 0.5% | Nov 23, 2024 | The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's memberlite_... |
| CVE-2024-11199 | MEDIUM | 5.4 | 1.0% | Nov 23, 2024 | The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rescue_progress... |
| CVE-2024-10519 | MEDIUM | 6.1 | 0.5% | Nov 23, 2024 | The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Sit... |
| CVE-2024-9942 | CRITICAL | 9.8 | 1.1% | Nov 23, 2024 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing ... |
| CVE-2024-9941 | HIGH | 8.8 | 0.6% | Nov 23, 2024 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing ... |
| CVE-2024-9660 | HIGH | 8.8 | 1.0% | Nov 23, 2024 | The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f... |
| CVE-2024-9659 | CRITICAL | 9.8 | 1.6% | Nov 23, 2024 | The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f... |
| CVE-2024-9511 | CRITICAL | 9.8 | 1.1% | Nov 23, 2024 | The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for Wo... |
| CVE-2024-10803 | HIGH | 7.5 | 0.9% | Nov 23, 2024 | The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now