2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10327 | HIGH | 8.1 | 0.6% | Oct 24, 2024 | A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification respo... |
| CVE-2024-45259 | MEDIUM | 6.5 | 0.2% | Oct 24, 2024 | An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By inte... |
| CVE-2024-45242 | HIGH | 7.8 | 34.7% | Oct 24, 2024 | EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metachar... |
| CVE-2024-48454 | HIGH | 7.2 | 0.9% | Oct 24, 2024 | An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via ... |
| CVE-2024-48427 | HIGH | 8.8 | 0.9% | Oct 24, 2024 | A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated us... |
| CVE-2024-48145 | CRITICAL | 9.1 | 0.5% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to a... |
| CVE-2024-48144 | CRITICAL | 9.1 | 0.5% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attacke... |
| CVE-2024-48143 | CRITICAL | 9.1 | 0.4% | Oct 24, 2024 | A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers t... |
| CVE-2024-48142 | HIGH | 7.5 | 0.4% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows at... |
| CVE-2024-48141 | HIGH | 7.5 | 0.4% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate a... |
| CVE-2024-48140 | HIGH | 7.5 | 0.4% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v... |
| CVE-2024-48139 | HIGH | 7.5 | 0.5% | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all pre... |
| CVE-2024-47173 | MEDIUM | 5.5 | 0.3% | Oct 24, 2024 | Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version ... |
| CVE-2024-46998 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Ed... |
| CVE-2024-46996 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Bl... |
| CVE-2024-46995 | MEDIUM | 6.1 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 4... |
| CVE-2024-46994 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog p... |
| CVE-2024-48514 | CRITICAL | 9.8 | 1.0% | Oct 24, 2024 | php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is abl... |
| CVE-2024-48442 | MEDIUM | 6.5 | 0.3% | Oct 24, 2024 | Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2... |
| CVE-2024-48441 | HIGH | 8.8 | 1.6% | Oct 24, 2024 | Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain... |
| CVE-2024-48440 | HIGH | 8.8 | 1.6% | Oct 24, 2024 | Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered t... |
| CVE-2024-46478 | CRITICAL | 9.8 | 0.7% | Oct 24, 2024 | HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. |
| CVE-2024-38314 | MEDIUM | 5.9 | 0.3% | Oct 24, 2024 | IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-... |
| CVE-2024-10338 | HIGH | 7.2 | 0.4% | Oct 24, 2024 | A vulnerability classified as critical was found in SourceCodeHero Clothes Recommendation System 1.0. Affected by this v... |
| CVE-2024-10337 | HIGH | 7.2 | 0.4% | Oct 24, 2024 | A vulnerability classified as critical has been found in SourceCodeHero Clothes Recommendation System 1.0. Affected is a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now