2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52378 | HIGH | 7.5 | 0.5% | Nov 14, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 DigiPass digipass... |
| CVE-2024-52377 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in bdthemes Instant Image Generator ai-image allows Upload... |
| CVE-2024-52376 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in cmsMinds Boat Rental Plugin for WordPress boat-rental-s... |
| CVE-2024-52375 | CRITICAL | 10 | 1.4% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative dat... |
| CVE-2024-52374 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in DoThatTask Do That Task do-that-task allows Upload a We... |
| CVE-2024-52373 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Team Devexhub Devexhub Gallery devexhub-gallery allows ... |
| CVE-2024-52372 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA easy-csv-importer ... |
| CVE-2024-52371 | HIGH | 8.6 | 0.6% | Nov 14, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DonnellC Global Gateway ... |
| CVE-2024-50831 | HIGH | 7.2 | 0.4% | Nov 14, 2024 | A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the usernam... |
| CVE-2024-50830 | HIGH | 7.2 | 0.4% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Proje... |
| CVE-2024-50829 | HIGH | 7.2 | 0.4% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0... |
| CVE-2024-50828 | HIGH | 7.2 | 0.4% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project ... |
| CVE-2024-50827 | HIGH | 7.2 | 0.4% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 ... |
| CVE-2024-50826 | HIGH | 7.2 | 0.4% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 ... |
| CVE-2024-50825 | HIGH | 7.2 | 0.4% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 ... |
| CVE-2024-50824 | HIGH | 7.2 | 0.5% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via th... |
| CVE-2024-50823 | CRITICAL | 9.8 | 0.5% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via th... |
| CVE-2024-4343 | CRITICAL | 9.8 | 2.6% | Nov 14, 2024 | A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/... |
| CVE-2024-4311 | MEDIUM | 5.4 | 0.5% | Nov 14, 2024 | zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password chan... |
| CVE-2024-49362 | CRITICAL | 9.6 | 1.0% | Nov 14, 2024 | Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote... |
| CVE-2024-48284 | MEDIUM | 4.8 | 0.5% | Nov 14, 2024 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Reg... |
| CVE-2024-3502 | HIGH | 8.1 | 0.4% | Nov 14, 2024 | In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account rec... |
| CVE-2024-3501 | HIGH | 8.1 | 0.4% | Nov 14, 2024 | In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclus... |
| CVE-2024-3379 | HIGH | 8.1 | 0.4% | Nov 14, 2024 | In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to ... |
| CVE-2024-1682 | MEDIUM | 4.3 | 0.4% | Nov 14, 2024 | An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now