2024 CVE Vulnerabilities
39,233 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50489 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-wo... |
| CVE-2024-50487 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authe... |
| CVE-2024-50486 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allo... |
| CVE-2024-50477 | CRITICAL | 9.8 | 8.0% | Oct 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile... |
| CVE-2024-50450 | CRITICAL | 9.8 | 1.2% | Oct 28, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxon... |
| CVE-2024-50442 | HIGH | 7.2 | 0.5% | Oct 28, 2024 | Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-a... |
| CVE-2024-50416 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer ... |
| CVE-2024-50408 | HIGH | 8.8 | 0.5% | Oct 28, 2024 | Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affec... |
| CVE-2024-48074 | HIGH | 8 | 0.7% | Oct 28, 2024 | An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a mali... |
| CVE-2024-10446 | HIGH | 7.2 | 0.5% | Oct 28, 2024 | A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an ... |
| CVE-2024-38821 | CRITICAL | 9.1 | 1.7% | Oct 28, 2024 | Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under cert... |
| CVE-2024-9162 | HIGH | 7.2 | 2.7% | Oct 28, 2024 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing... |
| CVE-2024-50307 | MEDIUM | 5.5 | 0.3% | Oct 28, 2024 | Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If... |
| CVE-2024-48936 | MEDIUM | 5 | 0.3% | Oct 28, 2024 | SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit a... |
| CVE-2024-10440 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitra... |
| CVE-2024-10439 | HIGH | 7.5 | 0.4% | Oct 28, 2024 | The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote ... |
| CVE-2024-10438 | HIGH | 7.5 | 0.5% | Oct 28, 2024 | The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypas... |
| CVE-2024-23843 | LOW | 2.2 | 0.2% | Oct 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC... |
| CVE-2024-50067 | HIGH | 7.8 | 0.2% | Oct 28, 2024 | In the Linux kernel, the following vulnerability has been resolved: uprobe: avoid out-of-bounds memory access of fetchi... |
| CVE-2024-10435 | MEDIUM | 6.3 | 1.2% | Oct 28, 2024 | A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown... |
| CVE-2024-10434 | CRITICAL | 9.8 | 1.2% | Oct 28, 2024 | A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This affects the function ... |
| CVE-2024-50624 | MEDIUM | 5.9 | 0.3% | Oct 28, 2024 | ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled m... |
| CVE-2024-50623 | CRITICAL | 9.8 | 98.5% | Oct 28, 2024 | In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up... |
| CVE-2024-10433 | MEDIUM | 6.1 | 0.4% | Oct 28, 2024 | A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affecte... |
| CVE-2024-10432 | CRITICAL | 9.8 | 0.6% | Oct 28, 2024 | A vulnerability has been found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as critical. Affec... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now