2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53506 | CRITICAL | 9.8 | 0.5% | Nov 29, 2024 | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs. |
| CVE-2024-53505 | CRITICAL | 9.8 | 0.5% | Nov 29, 2024 | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent. |
| CVE-2024-53504 | CRITICAL | 9.8 | 0.6% | Nov 29, 2024 | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory. |
| CVE-2024-35368 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c. |
| CVE-2024-35367 | CRITICAL | 9.1 | 0.7% | Nov 29, 2024 | FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer |
| CVE-2024-35366 | CRITICAL | 9.1 | 0.6% | Nov 29, 2024 | FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavfo... |
| CVE-2024-36622 | CRITICAL | 9.8 | 2.8% | Nov 29, 2024 | In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vuln... |
| CVE-2024-49806 | CRITICAL | 9.8 | 0.3% | Nov 29, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryp... |
| CVE-2024-49805 | CRITICAL | 9.8 | 0.3% | Nov 29, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryp... |
| CVE-2024-52782 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code... |
| CVE-2024-52781 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code... |
| CVE-2024-52780 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code... |
| CVE-2024-52779 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code... |
| CVE-2024-52778 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code... |
| CVE-2024-52777 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L, <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Cod... |
| CVE-2024-48406 | CRITICAL | 9.8 | 0.9% | Nov 29, 2024 | Buffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbi... |
| CVE-2024-36671 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules... |
| CVE-2024-11992 | CRITICAL | 9.1 | 0.8% | Nov 29, 2024 | Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to b... |
| CVE-2024-50357 | CRITICAL | 9.8 | 0.6% | Nov 29, 2024 | FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in t... |
| CVE-2024-11482 | CRITICAL | 9.8 | 2.5% | Nov 29, 2024 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code exe... |
| CVE-2024-11979 | CRITICAL | 9.8 | 0.8% | Nov 29, 2024 | DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This all... |
| CVE-2024-11970 | CRITICAL | 9.8 | 0.8% | Nov 28, 2024 | A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is a... |
| CVE-2024-11967 | CRITICAL | 9.8 | 0.7% | Nov 28, 2024 | A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is... |
| CVE-2024-11966 | CRITICAL | 9.8 | 0.8% | Nov 28, 2024 | A vulnerability was found in PHPGurukul Complaint Management system 1.0 and classified as critical. This issue affects s... |
| CVE-2024-52338 | CRITICAL | 9.8 | 2.3% | Nov 28, 2024 | Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now