2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45970 | CRITICAL | 9.8 | 0.6% | Nov 15, 2024 | Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd75626... |
| CVE-2024-11250 | CRITICAL | 9.8 | 0.7% | Nov 15, 2024 | A vulnerability was found in code-projects Inventory Management up to 1.0. It has been declared as critical. This vulner... |
| CVE-2024-52528 | CRITICAL | 9.3 | 0.6% | Nov 15, 2024 | Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for... |
| CVE-2024-51164 | CRITICAL | 9.1 | 0.7% | Nov 15, 2024 | Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allo... |
| CVE-2024-50724 | CRITICAL | 9.8 | 0.4% | Nov 15, 2024 | KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp. |
| CVE-2024-50649 | CRITICAL | 9.8 | 1.0% | Nov 15, 2024 | The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability. |
| CVE-2024-50648 | CRITICAL | 9.8 | 1.0% | Nov 15, 2024 | yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improp... |
| CVE-2024-11244 | CRITICAL | 9.8 | 0.7% | Nov 15, 2024 | A vulnerability classified as critical was found in code-projects Farmacia 1.0. This vulnerability affects unknown code ... |
| CVE-2024-11237 | CRITICAL | 9.8 | 5.2% | Nov 15, 2024 | A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this... |
| CVE-2024-10534 | CRITICAL | 9.8 | 0.4% | Nov 15, 2024 | Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Contr... |
| CVE-2024-10443 | CRITICAL | 9.8 | 28.4% | Nov 15, 2024 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager... |
| CVE-2024-10924 | CRITICAL | 9.8 | 81.7% | Nov 15, 2024 | The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass ... |
| CVE-2024-11120 | CRITICAL | 9.8 | 28.6% | Nov 15, 2024 | Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit t... |
| CVE-2024-52308 | CRITICAL | 9.6 | 0.9% | Nov 14, 2024 | The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH serve... |
| CVE-2024-48974 | CRITICAL | 9.3 | 0.2% | Nov 14, 2024 | The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for ... |
| CVE-2024-48973 | CRITICAL | 9.3 | 0.2% | Nov 14, 2024 | The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and rece... |
| CVE-2024-48971 | CRITICAL | 9.3 | 0.2% | Nov 14, 2024 | The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This c... |
| CVE-2024-48970 | CRITICAL | 9.3 | 0.2% | Nov 14, 2024 | The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and r... |
| CVE-2024-48967 | CRITICAL | 10 | 0.6% | Nov 14, 2024 | The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activit... |
| CVE-2024-48966 | CRITICAL | 10 | 0.7% | Nov 14, 2024 | The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An a... |
| CVE-2024-31695 | CRITICAL | 9.8 | 0.7% | Nov 14, 2024 | A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attacker... |
| CVE-2024-9834 | CRITICAL | 9.3 | 0.1% | Nov 14, 2024 | Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that ... |
| CVE-2024-9832 | CRITICAL | 9.3 | 0.2% | Nov 14, 2024 | There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clin... |
| CVE-2024-52370 | CRITICAL | 9.9 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support hive-support allows Upload a ... |
| CVE-2024-52369 | CRITICAL | 9.9 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Optimal Access KBucket kbucket allows Upload a Web Shel... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now