2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50421 | MEDIUM | 5.3 | 0.4% | Oct 29, 2024 | Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-pa... |
| CVE-2024-48573 | CRITICAL | 9.8 | 1.0% | Oct 29, 2024 | A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and admin... |
| CVE-2024-48572 | MEDIUM | 5.3 | 0.4% | Oct 29, 2024 | A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addres... |
| CVE-2024-48138 | CRITICAL | 9.8 | 0.8% | Oct 29, 2024 | A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16... |
| CVE-2024-44081 | CRITICAL | 9.8 | 0.7% | Oct 29, 2024 | In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in ... |
| CVE-2024-44080 | HIGH | 7.5 | 0.5% | Oct 29, 2024 | In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resul... |
| CVE-2024-10488 | HIGH | 8.8 | 0.5% | Oct 29, 2024 | Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-10487 | HIGH | 8.8 | 0.7% | Oct 29, 2024 | Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds m... |
| CVE-2024-10228 | LOW | 3.3 | 0.1% | Oct 29, 2024 | The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified... |
| CVE-2024-8587 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Ov... |
| CVE-2024-50456 | HIGH | 8.8 | 0.3% | Oct 29, 2024 | Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce... |
| CVE-2024-50455 | HIGH | 8.8 | 0.4% | Oct 29, 2024 | Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce... |
| CVE-2024-48461 | MEDIUM | 4.8 | 0.4% | Oct 29, 2024 | Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitr... |
| CVE-2024-48206 | CRITICAL | 9.8 | 0.8% | Oct 29, 2024 | A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code. |
| CVE-2024-48063 | CRITICAL | 9.8 | 1.6% | Oct 29, 2024 | In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is... |
| CVE-2024-48955 | HIGH | 8.1 | 0.6% | Oct 29, 2024 | Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functi... |
| CVE-2024-9990 | HIGH | 8.8 | 0.3% | Oct 29, 2024 | The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This... |
| CVE-2024-9989 | CRITICAL | 9.8 | 7.2% | Oct 29, 2024 | The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is d... |
| CVE-2024-9988 | CRITICAL | 9.8 | 1.1% | Oct 29, 2024 | The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is d... |
| CVE-2024-8924 | HIGH | 7.5 | 0.5% | Oct 29, 2024 | ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability... |
| CVE-2024-50466 | HIGH | 8.8 | 0.2% | Oct 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkm... |
| CVE-2024-50459 | CRITICAL | 9.8 | 0.4% | Oct 29, 2024 | Missing Authorization vulnerability in Hossni Mubarak AidWP wp-stripe-donation allows Exploiting Incorrectly Configured ... |
| CVE-2024-10491 | MEDIUM | 5.3 | 0.4% | Oct 29, 2024 | A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in... |
| CVE-2024-8923 | CRITICAL | 10 | 1.1% | Oct 29, 2024 | ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability c... |
| CVE-2024-7985 | HIGH | 8.8 | 2.2% | Oct 29, 2024 | The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now