2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42450 | CRITICAL | 10 | 0.6% | Nov 19, 2024 | The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Av... |
| CVE-2024-52402 | CRITICAL | 9.6 | 0.8% | Nov 19, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in gunghoinc Exclusive Content Password Protect exclusive-content-passwo... |
| CVE-2024-52401 | CRITICAL | 9.6 | 0.3% | Nov 19, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog DownloadManager hacklog-downloadmanager allows... |
| CVE-2024-52675 | CRITICAL | 9.8 | 0.5% | Nov 19, 2024 | SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php. |
| CVE-2024-11036 | CRITICAL | 9.8 | 0.7% | Nov 19, 2024 | The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for Wo... |
| CVE-2024-11069 | CRITICAL | 9.1 | 0.4% | Nov 19, 2024 | The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on ... |
| CVE-2024-51051 | CRITICAL | 9.8 | 0.5% | Nov 18, 2024 | AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account. |
| CVE-2024-51053 | CRITICAL | 9.8 | 0.6% | Nov 18, 2024 | An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execut... |
| CVE-2024-50919 | CRITICAL | 9.8 | 1.1% | Nov 18, 2024 | Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file format... |
| CVE-2024-47533 | CRITICAL | 9.8 | 3.9% | Nov 18, 2024 | Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper a... |
| CVE-2024-44756 | CRITICAL | 9.8 | 0.5% | Nov 18, 2024 | NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter... |
| CVE-2024-0012 | CRITICAL | 9.8 | 99.7% | Nov 18, 2024 | An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access t... |
| CVE-2024-52434 | CRITICAL | 9.1 | 1.1% | Nov 18, 2024 | Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Inject... |
| CVE-2024-52433 | CRITICAL | 9.8 | 3.1% | Nov 18, 2024 | Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Obj... |
| CVE-2024-52432 | CRITICAL | 9.8 | 0.5% | Nov 18, 2024 | Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Obje... |
| CVE-2024-52431 | CRITICAL | 9.8 | 0.4% | Nov 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressaholic WordPr... |
| CVE-2024-52430 | CRITICAL | 9.8 | 1.1% | Nov 18, 2024 | Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.T... |
| CVE-2024-52428 | CRITICAL | 9.8 | 0.5% | Nov 18, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-52316 | CRITICAL | 9.8 | 6.3% | Nov 18, 2024 | Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication... |
| CVE-2024-42383 | CRITICAL | 9.8 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value ... |
| CVE-2024-47208 | CRITICAL | 9.8 | 1.6% | Nov 18, 2024 | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OF... |
| CVE-2024-11315 | CRITICAL | 9.8 | 1.3% | Nov 18, 2024 | The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un... |
| CVE-2024-11314 | CRITICAL | 9.8 | 1.3% | Nov 18, 2024 | The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un... |
| CVE-2024-11313 | CRITICAL | 9.8 | 1.3% | Nov 18, 2024 | The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un... |
| CVE-2024-11312 | CRITICAL | 9.8 | 1.3% | Nov 18, 2024 | The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now