2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11320 | CRITICAL | 9.8 | 90.5% | Nov 21, 2024 | Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication me... |
| CVE-2024-51151 | CRITICAL | 9.8 | 29.7% | Nov 21, 2024 | D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter ... |
| CVE-2024-52765 | CRITICAL | 9.8 | 11.2% | Nov 20, 2024 | H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter. |
| CVE-2024-52677 | CRITICAL | 9.8 | 0.6% | Nov 20, 2024 | HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php. |
| CVE-2024-48984 | CRITICAL | 9.8 | 0.5% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the... |
| CVE-2024-33439 | CRITICAL | 9.1 | 0.5% | Nov 20, 2024 | An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary O... |
| CVE-2024-29292 | CRITICAL | 9.1 | 1.0% | Nov 20, 2024 | Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated re... |
| CVE-2024-52771 | CRITICAL | 9.1 | 0.6% | Nov 20, 2024 | DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_v... |
| CVE-2024-52770 | CRITICAL | 9.8 | 0.8% | Nov 20, 2024 | An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to... |
| CVE-2024-10094 | CRITICAL | 9.8 | 0.5% | Nov 20, 2024 | Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code |
| CVE-2024-9479 | CRITICAL | 10 | 0.4% | Nov 20, 2024 | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Esc... |
| CVE-2024-9478 | CRITICAL | 10 | 0.4% | Nov 20, 2024 | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Esc... |
| CVE-2024-52443 | CRITICAL | 9.8 | 0.5% | Nov 20, 2024 | Deserialization of Untrusted Data vulnerability in masikonis Geolocator geolocator allows Object Injection.This issue af... |
| CVE-2024-52442 | CRITICAL | 9.8 | 0.5% | Nov 20, 2024 | Incorrect Privilege Assignment vulnerability in userplus UserPlus userplus allows Privilege Escalation.This issue affect... |
| CVE-2024-52441 | CRITICAL | 9.8 | 0.5% | Nov 20, 2024 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoc... |
| CVE-2024-52440 | CRITICAL | 9.8 | 0.5% | Nov 20, 2024 | Deserialization of Untrusted Data vulnerability in xpresslane Xpresslane Fast Checkout xpresslane-integration-for-woocom... |
| CVE-2024-52439 | CRITICAL | 9.8 | 0.5% | Nov 20, 2024 | Deserialization of Untrusted Data vulnerability in Mark O'Donnell Team Rosters team-rosters allows Object Injection.This... |
| CVE-2024-10127 | CRITICAL | 9.8 | 0.6% | Nov 20, 2024 | Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLD... |
| CVE-2024-52360 | CRITICAL | 9.8 | 0.4% | Nov 19, 2024 | IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send speci... |
| CVE-2024-52759 | CRITICAL | 9.8 | 5.2% | Nov 19, 2024 | D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp funct... |
| CVE-2024-52714 | CRITICAL | 9.8 | 0.6% | Nov 19, 2024 | Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime. |
| CVE-2024-48694 | CRITICAL | 9.8 | 1.0% | Nov 19, 2024 | File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote att... |
| CVE-2024-48072 | CRITICAL | 9.8 | 0.4% | Nov 19, 2024 | Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?inv... |
| CVE-2024-48070 | CRITICAL | 9.8 | 0.7% | Nov 19, 2024 | An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malic... |
| CVE-2024-48069 | CRITICAL | 9.8 | 0.4% | Nov 19, 2024 | A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to uploa... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now