2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10672 | LOW | 2.7 | 0.5% | Nov 12, 2024 | The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie... |
| CVE-2024-10538 | MEDIUM | 5.4 | 0.2% | Nov 12, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label pa... |
| CVE-2024-49395 | MEDIUM | 5.3 | 0.2% | Nov 12, 2024 | In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field b... |
| CVE-2024-49394 | MEDIUM | 5.3 | 0.3% | Nov 12, 2024 | In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacke... |
| CVE-2024-8882 | MEDIUM | 4.5 | 0.2% | Nov 12, 2024 | A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and ea... |
| CVE-2024-8881 | MEDIUM | 6.8 | 0.7% | Nov 12, 2024 | A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version ... |
| CVE-2024-49393 | MEDIUM | 6.5 | 0.3% | Nov 12, 2024 | In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker tha... |
| CVE-2024-11099 | CRITICAL | 9.8 | 0.6% | Nov 12, 2024 | A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. This issue affects some unkno... |
| CVE-2024-11097 | MEDIUM | 5.5 | 0.3% | Nov 12, 2024 | A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. Thi... |
| CVE-2024-47595 | HIGH | 7.1 | 0.1% | Nov 12, 2024 | An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access.... |
| CVE-2024-47593 | MEDIUM | 4.3 | 0.4% | Nov 12, 2024 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the serv... |
| CVE-2024-47592 | MEDIUM | 5.3 | 0.3% | Nov 12, 2024 | SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the... |
| CVE-2024-47590 | HIGH | 8.8 | 0.8% | Nov 12, 2024 | An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated vi... |
| CVE-2024-47588 | MEDIUM | 4.7 | 0.1% | Nov 12, 2024 | In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors,... |
| CVE-2024-47587 | LOW | 3.5 | 0.2% | Nov 12, 2024 | Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of pri... |
| CVE-2024-47586 | MEDIUM | 5.3 | 3.6% | Nov 12, 2024 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously cra... |
| CVE-2024-42372 | MEDIUM | 6.5 | 0.3% | Nov 12, 2024 | Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read a... |
| CVE-2024-11096 | MEDIUM | 6.5 | 0.5% | Nov 12, 2024 | A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown ... |
| CVE-2024-11079 | MEDIUM | 5.5 | 0.5% | Nov 12, 2024 | A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hos... |
| CVE-2024-52533 | CRITICAL | 9.8 | 1.3% | Nov 11, 2024 | gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CON... |
| CVE-2024-51213 | MEDIUM | 6.1 | 0.3% | Nov 11, 2024 | Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-50636 | CRITICAL | 9.8 | 1.2% | Nov 11, 2024 | PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code e... |
| CVE-2024-50601 | MEDIUM | 6.1 | 0.2% | Nov 11, 2024 | Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to ve... |
| CVE-2024-25255 | CRITICAL | 9.8 | 1.4% | Nov 11, 2024 | Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multip... |
| CVE-2024-25254 | CRITICAL | 9.8 | 0.4% | Nov 11, 2024 | SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now