2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40579 | MEDIUM | 5.4 | 0.3% | Nov 14, 2024 | Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to ... |
| CVE-2024-39707 | MEDIUM | 5.3 | 0.2% | Nov 14, 2024 | Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by def... |
| CVE-2024-31695 | CRITICAL | 9.8 | 0.7% | Nov 14, 2024 | A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attacker... |
| CVE-2024-9834 | CRITICAL | 9.3 | 0.1% | Nov 14, 2024 | Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that ... |
| CVE-2024-9832 | CRITICAL | 9.3 | 0.2% | Nov 14, 2024 | There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clin... |
| CVE-2024-51687 | HIGH | 7.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This is... |
| CVE-2024-51684 | HIGH | 7.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issu... |
| CVE-2024-51688 | HIGH | 7.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verific... |
| CVE-2024-49025 | MEDIUM | 4.3 | 0.5% | Nov 14, 2024 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-10397 | HIGH | 7.8 | 0.4% | Nov 14, 2024 | A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code. |
| CVE-2024-10396 | MEDIUM | 6.5 | 0.5% | Nov 14, 2024 | An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, pos... |
| CVE-2024-10394 | HIGH | 7.8 | 0.2% | Nov 14, 2024 | A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing th... |
| CVE-2024-52370 | CRITICAL | 9.9 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support hive-support allows Upload a ... |
| CVE-2024-52369 | CRITICAL | 9.9 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Optimal Access KBucket kbucket allows Upload a Web Shel... |
| CVE-2024-3760 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bom... |
| CVE-2024-5125 | HIGH | 7.3 | 0.3% | Nov 14, 2024 | parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input ... |
| CVE-2024-52524 | MEDIUM | 6.9 | 0.8% | Nov 14, 2024 | Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discove... |
| CVE-2024-52396 | HIGH | 8.8 | 0.6% | Nov 14, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-edi... |
| CVE-2024-52393 | HIGH | 7.2 | 0.5% | Nov 14, 2024 | Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-... |
| CVE-2024-52384 | CRITICAL | 9.9 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, ... |
| CVE-2024-52383 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in On... |
| CVE-2024-52382 | CRITICAL | 9.8 | 1.0% | Nov 14, 2024 | Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue ... |
| CVE-2024-52381 | HIGH | 8.1 | 0.6% | Nov 14, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-52380 | CRITICAL | 10 | 1.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web... |
| CVE-2024-52379 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in faizalbahasan kineticPay for WooCommerce kineticpay-for... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now