2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47549 | MEDIUM | 6.1 | 0.3% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of uninte... |
| CVE-2024-47406 | CRITICAL | 9.8 | 0.6% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulner... |
| CVE-2024-47005 | HIGH | 8.1 | 0.5% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users on... |
| CVE-2024-45842 | MEDIUM | 5.3 | 0.5% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability.... |
| CVE-2024-45829 | HIGH | 7.5 | 0.7% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly... |
| CVE-2024-43424 | HIGH | 7.5 | 0.7% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. C... |
| CVE-2024-42420 | HIGH | 7.5 | 0.7% | Oct 25, 2024 | Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword se... |
| CVE-2024-10148 | MEDIUM | 5.4 | 0.2% | Oct 25, 2024 | The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in... |
| CVE-2024-10011 | HIGH | 8.1 | 0.9% | Oct 25, 2024 | The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 vi... |
| CVE-2024-9488 | CRITICAL | 9.8 | 0.8% | Oct 25, 2024 | The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including... |
| CVE-2024-9109 | MEDIUM | 4.3 | 0.4% | Oct 25, 2024 | The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modificat... |
| CVE-2024-9686 | MEDIUM | 5.3 | 0.3% | Oct 25, 2024 | The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a mis... |
| CVE-2024-10372 | LOW | 3.6 | 0.3% | Oct 25, 2024 | A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This vulnerability affects the function... |
| CVE-2024-10371 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the ... |
| CVE-2024-10370 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue... |
| CVE-2024-10369 | CRITICAL | 9.8 | 0.8% | Oct 25, 2024 | A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vu... |
| CVE-2024-10368 | CRITICAL | 9.8 | 0.7% | Oct 25, 2024 | A vulnerability was found in Codezips Sales Management System 1.0. It has been classified as critical. Affected is an un... |
| CVE-2024-10355 | MEDIUM | 4.9 | 1.0% | Oct 25, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0.... |
| CVE-2024-10354 | MEDIUM | 4.9 | 0.7% | Oct 25, 2024 | A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this... |
| CVE-2024-10353 | HIGH | 7.2 | 0.5% | Oct 25, 2024 | A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. Affected is an unknown f... |
| CVE-2024-10351 | HIGH | 8.8 | 0.8% | Oct 25, 2024 | A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function s... |
| CVE-2024-10350 | CRITICAL | 9.8 | 0.5% | Oct 24, 2024 | A vulnerability was found in code-projects Hospital Management System 1.0. It has been declared as critical. This vulner... |
| CVE-2024-49762 | MEDIUM | 4.6 | 0.1% | Oct 24, 2024 | Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the ... |
| CVE-2024-49760 | MEDIUM | 5.3 | 0.6% | Oct 24, 2024 | OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter... |
| CVE-2024-49750 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now