2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21541 | CRITICAL | 9.8 | 1.1% | Nov 13, 2024 | Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function ... |
| CVE-2024-11150 | CRITICAL | 9.8 | 1.3% | Nov 13, 2024 | The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p... |
| CVE-2024-10575 | CRITICAL | 9.8 | 0.6% | Nov 13, 2024 | CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and... |
| CVE-2024-10828 | CRITICAL | 9.8 | 1.4% | Nov 13, 2024 | The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up ... |
| CVE-2024-10820 | CRITICAL | 9.8 | 1.2% | Nov 13, 2024 | The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2024-39712 | CRITICAL | 9.1 | 1.7% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version... |
| CVE-2024-39711 | CRITICAL | 9.1 | 1.7% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version... |
| CVE-2024-39710 | CRITICAL | 9.1 | 1.9% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version... |
| CVE-2024-38656 | CRITICAL | 9.1 | 1.7% | Nov 13, 2024 | Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version... |
| CVE-2024-28729 | CRITICAL | 9.8 | 0.6% | Nov 12, 2024 | An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to e... |
| CVE-2024-10218 | CRITICAL | 9.2 | 0.5% | Nov 12, 2024 | XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO... |
| CVE-2024-10217 | CRITICAL | 9.2 | 0.5% | Nov 12, 2024 | XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO... |
| CVE-2024-26011 | CRITICAL | 9.8 | 0.6% | Nov 12, 2024 | A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4... |
| CVE-2024-43639 | CRITICAL | 9.8 | 8.7% | Nov 12, 2024 | Windows KDC Proxy Remote Code Execution Vulnerability |
| CVE-2024-43602 | CRITICAL | 9.9 | 2.2% | Nov 12, 2024 | Azure CycleCloud Remote Code Execution Vulnerability |
| CVE-2024-43498 | CRITICAL | 9.8 | 3.5% | Nov 12, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability |
| CVE-2024-11138 | CRITICAL | 9.8 | 2.5% | Nov 12, 2024 | A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /d... |
| CVE-2024-49369 | CRITICAL | 9.8 | 2.9% | Nov 12, 2024 | Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generat... |
| CVE-2024-10943 | CRITICAL | 9.1 | 0.5% | Nov 12, 2024 | An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets ac... |
| CVE-2024-50330 | CRITICAL | 9.8 | 40.5% | Nov 12, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-43415 | CRITICAL | 9 | 0.7% | Nov 12, 2024 | An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_aw... |
| CVE-2024-8074 | CRITICAL | 9.3 | 0.4% | Nov 12, 2024 | Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows... |
| CVE-2024-50386 | CRITICAL | 9.9 | 1.4% | Nov 12, 2024 | Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary... |
| CVE-2024-50557 | CRITICAL | 9.8 | 0.9% | Nov 12, 2024 | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM... |
| CVE-2024-46890 | CRITICAL | 9.4 | 0.7% | Nov 12, 2024 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now