2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45887 | HIGH | 8 | 2.1% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45885 | HIGH | 8 | 1.3% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45884 | HIGH | 8 | 2.1% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when... |
| CVE-2024-45882 | HIGH | 8 | 1.5% | Nov 4, 2024 | DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parame... |
| CVE-2024-51672 | HIGH | 7.2 | 0.5% | Nov 4, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper Better... |
| CVE-2024-51665 | MEDIUM | 4.3 | 0.5% | Nov 4, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor ... |
| CVE-2024-51582 | HIGH | 8.8 | 0.5% | Nov 4, 2024 | Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion... |
| CVE-2024-51408 | MEDIUM | 6.5 | 0.5% | Nov 4, 2024 | AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to ... |
| CVE-2024-51253 | HIGH | 8 | 0.7% | Nov 4, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51251 | HIGH | 8 | 0.7% | Nov 4, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51249 | HIGH | 8 | 0.7% | Nov 4, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51246 | HIGH | 8 | 0.4% | Nov 4, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-50531 | CRITICAL | 9.8 | 0.5% | Nov 4, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toa... |
| CVE-2024-50530 | HIGH | 8.8 | 0.5% | Nov 4, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer al... |
| CVE-2024-50529 | HIGH | 8.8 | 0.5% | Nov 4, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a We... |
| CVE-2024-50528 | HIGH | 7.5 | 0.4% | Nov 4, 2024 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Bui... |
| CVE-2024-50527 | CRITICAL | 9.8 | 0.5% | Nov 4, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-buil... |
| CVE-2024-50526 | CRITICAL | 9.8 | 0.6% | Nov 4, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose... |
| CVE-2024-50525 | CRITICAL | 9.8 | 0.5% | Nov 4, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in helloprint Helloprint helloprint allows Upload a Web Sh... |
| CVE-2024-50523 | CRITICAL | 9.8 | 0.5% | Nov 4, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allpost-contactf... |
| CVE-2024-45164 | HIGH | 7.1 | 0.3% | Nov 4, 2024 | Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the la... |
| CVE-2024-9147 | MEDIUM | 6.1 | 0.2% | Nov 4, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik... |
| CVE-2024-51561 | HIGH | 7.5 | 0.5% | Nov 4, 2024 | This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. A... |
| CVE-2024-51560 | MEDIUM | 4.3 | 0.3% | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint.... |
| CVE-2024-51559 | MEDIUM | 6.5 | 0.3% | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticate... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now