2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11965 | CRITICAL | 9.8 | 0.8% | Nov 28, 2024 | A vulnerability has been found in PHPGurukul Complaint Management system 1.0 and classified as critical. This vulnerabil... |
| CVE-2024-11964 | CRITICAL | 9.8 | 0.8% | Nov 28, 2024 | A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management system 1.0. This affects... |
| CVE-2024-11962 | CRITICAL | 9.8 | 0.9% | Nov 28, 2024 | A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnera... |
| CVE-2024-52490 | CRITICAL | 10 | 0.6% | Nov 28, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in pathomation Pathomation pathomation allows Upload a Web... |
| CVE-2024-52475 | CRITICAL | 9.8 | 1.8% | Nov 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Information Technology Wawp automation-web-pla... |
| CVE-2024-52474 | CRITICAL | 9.3 | 0.5% | Nov 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Сервис “Экспресс П... |
| CVE-2024-8672 | CRITICAL | 9.9 | 43.8% | Nov 28, 2024 | The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Ex... |
| CVE-2024-11103 | CRITICAL | 9.8 | 0.7% | Nov 28, 2024 | The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up t... |
| CVE-2024-11082 | CRITICAL | 9.9 | 1.2% | Nov 28, 2024 | The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2024-11925 | CRITICAL | 9.8 | 0.6% | Nov 28, 2024 | The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi... |
| CVE-2024-41126 | CRITICAL | 9.6 | 0.3% | Nov 27, 2024 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be tr... |
| CVE-2024-41125 | CRITICAL | 9.6 | 0.3% | Nov 27, 2024 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be tr... |
| CVE-2024-9369 | CRITICAL | 9.6 | 0.6% | Nov 27, 2024 | Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromis... |
| CVE-2024-46054 | CRITICAL | 9.8 | 0.8% | Nov 27, 2024 | OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, all... |
| CVE-2024-53604 | CRITICAL | 9.8 | 1.0% | Nov 27, 2024 | A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management S... |
| CVE-2024-42330 | CRITICAL | 9.1 | 1.0% | Nov 27, 2024 | The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem ... |
| CVE-2024-42327 | CRITICAL | 9.9 | 78.8% | Nov 27, 2024 | A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access... |
| CVE-2024-11667 | CRITICAL | 9.8 | 3.0% | Nov 27, 2024 | A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through ... |
| CVE-2024-53676 | CRITICAL | 9.8 | 51.3% | Nov 27, 2024 | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution... |
| CVE-2024-11819 | CRITICAL | 9.8 | 0.6% | Nov 27, 2024 | A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerabilit... |
| CVE-2024-11818 | CRITICAL | 9.8 | 0.6% | Nov 27, 2024 | A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System... |
| CVE-2024-11817 | CRITICAL | 9.8 | 0.6% | Nov 26, 2024 | A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as c... |
| CVE-2024-53673 | CRITICAL | 9.8 | 0.7% | Nov 26, 2024 | A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code... |
| CVE-2024-50942 | CRITICAL | 9.8 | 0.6% | Nov 26, 2024 | qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml. |
| CVE-2024-11745 | CRITICAL | 9.8 | 1.3% | Nov 26, 2024 | A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function ro... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now