2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52009 | CRITICAL | 9.8 | 0.7% | Nov 8, 2024 | Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs ... |
| CVE-2024-35426 | CRITICAL | 9.8 | 0.6% | Nov 8, 2024 | vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c. |
| CVE-2024-48073 | CRITICAL | 9.8 | 1.2% | Nov 8, 2024 | sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is ... |
| CVE-2024-51211 | CRITICAL | 9.8 | 2.2% | Nov 8, 2024 | SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The... |
| CVE-2024-50811 | CRITICAL | 9.1 | 0.4% | Nov 8, 2024 | hopetree izone lts c011b48 contains a server-side request forgery (SSRF) vulnerability in the active push function as \\... |
| CVE-2024-50966 | CRITICAL | 9.3 | 0.3% | Nov 8, 2024 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.... |
| CVE-2024-45764 | CRITICAL | 9.8 | 0.5% | Nov 8, 2024 | Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. A... |
| CVE-2024-50588 | CRITICAL | 9.8 | 0.7% | Nov 8, 2024 | An unauthenticated attacker with access to the local network of the medical office can use known default credentials to... |
| CVE-2024-10998 | CRITICAL | 9.8 | 0.7% | Nov 8, 2024 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. This issue af... |
| CVE-2024-10997 | CRITICAL | 9.8 | 0.5% | Nov 8, 2024 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. This vulne... |
| CVE-2024-10996 | CRITICAL | 9.8 | 0.7% | Nov 8, 2024 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been classified as critical. This aff... |
| CVE-2024-10995 | CRITICAL | 9.8 | 0.7% | Nov 8, 2024 | A vulnerability was found in Codezips Hospital Appointment System 1.0 and classified as critical. Affected by this issue... |
| CVE-2024-7982 | CRITICAL | 9.6 | 0.7% | Nov 8, 2024 | The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters w... |
| CVE-2024-10991 | CRITICAL | 9.8 | 0.7% | Nov 8, 2024 | A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issu... |
| CVE-2024-10988 | CRITICAL | 9.1 | 0.6% | Nov 8, 2024 | A vulnerability was found in code-projects E-Health Care System 1.0. It has been rated as critical. Affected by this iss... |
| CVE-2024-50766 | CRITICAL | 9.8 | 0.5% | Nov 7, 2024 | SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter. |
| CVE-2024-10007 | CRITICAL | 9.1 | 0.8% | Nov 7, 2024 | A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed cont... |
| CVE-2024-10969 | CRITICAL | 9.8 | 0.6% | Nov 7, 2024 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. Affected by t... |
| CVE-2024-10968 | CRITICAL | 9.8 | 0.7% | Nov 7, 2024 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected b... |
| CVE-2024-47073 | CRITICAL | 9.1 | 1.2% | Nov 7, 2024 | DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into... |
| CVE-2024-10964 | CRITICAL | 9.8 | 0.6% | Nov 7, 2024 | A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_p... |
| CVE-2024-51504 | CRITICAL | 9.1 | 0.9% | Nov 7, 2024 | When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofin... |
| CVE-2024-51990 | CRITICAL | 9.3 | 0.6% | Nov 7, 2024 | jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cau... |
| CVE-2024-51736 | CRITICAL | 9.8 | 0.4% | Nov 6, 2024 | Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when a... |
| CVE-2024-51757 | CRITICAL | 9.3 | 0.7% | Nov 6, 2024 | happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom pr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now