2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10294 | HIGH | 7.5 | 0.3% | Nov 9, 2024 | The CE21 Suite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-10285 | HIGH | 7.5 | 0.6% | Nov 9, 2024 | The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the plugin-log.txt in versions... |
| CVE-2024-10284 | CRITICAL | 9.8 | 0.4% | Nov 9, 2024 | The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This... |
| CVE-2024-52314 | MEDIUM | 6.9 | 0.4% | Nov 9, 2024 | A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to ... |
| CVE-2024-52313 | MEDIUM | 5.3 | 0.3% | Nov 9, 2024 | An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the pa... |
| CVE-2024-52312 | MEDIUM | 5.4 | 0.3% | Nov 9, 2024 | Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to per... |
| CVE-2024-52311 | MEDIUM | 6.3 | 0.5% | Nov 9, 2024 | Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticat... |
| CVE-2024-10953 | MEDIUM | 5.3 | 0.3% | Nov 9, 2024 | An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.a... |
| CVE-2024-52009 | CRITICAL | 9.8 | 0.7% | Nov 8, 2024 | Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs ... |
| CVE-2024-52007 | HIGH | 8.6 | 0.9% | Nov 8, 2024 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing pe... |
| CVE-2024-52004 | HIGH | 8.7 | 0.7% | Nov 8, 2024 | MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has b... |
| CVE-2024-52002 | HIGH | 8.8 | 0.6% | Nov 8, 2024 | Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Reques... |
| CVE-2024-52001 | MEDIUM | 4.3 | 0.3% | Nov 8, 2024 | Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access for... |
| CVE-2024-52000 | MEDIUM | 6.1 | 0.4% | Nov 8, 2024 | Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site ... |
| CVE-2024-35427 | MEDIUM | 5.5 | 0.2% | Nov 8, 2024 | vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser.... |
| CVE-2024-35426 | CRITICAL | 9.8 | 0.6% | Nov 8, 2024 | vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c. |
| CVE-2024-48073 | CRITICAL | 9.8 | 1.2% | Nov 8, 2024 | sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is ... |
| CVE-2024-35425 | MEDIUM | 5.5 | 0.2% | Nov 8, 2024 | vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_funct... |
| CVE-2024-35424 | MEDIUM | 5.5 | 0.2% | Nov 8, 2024 | vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser.... |
| CVE-2024-35423 | HIGH | 7.8 | 0.3% | Nov 8, 2024 | vmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_w... |
| CVE-2024-35422 | HIGH | 7.8 | 0.3% | Nov 8, 2024 | vmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c. |
| CVE-2024-35421 | MEDIUM | 5.5 | 0.2% | Nov 8, 2024 | vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser... |
| CVE-2024-35420 | MEDIUM | 6.2 | 0.2% | Nov 8, 2024 | wac commit 385e1 was discovered to contain a heap overflow. |
| CVE-2024-35419 | MEDIUM | 5.5 | 0.2% | Nov 8, 2024 | wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerab... |
| CVE-2024-35418 | MEDIUM | 6.2 | 0.2% | Nov 8, 2024 | wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerabi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now