2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49227 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object I... |
| CVE-2024-49226 | HIGH | 8.8 | 0.5% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Obje... |
| CVE-2024-49218 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products... |
| CVE-2024-49216 | CRITICAL | 10 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in jclay06 Feed Comments Number feed-comments-number allow... |
| CVE-2024-48035 | CRITICAL | 9.9 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-searc... |
| CVE-2024-48034 | CRITICAL | 9.9 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in fliperrr Creates 3D Flipbook, PDF Flipbook create-flipb... |
| CVE-2024-48030 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object In... |
| CVE-2024-48029 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-48028 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affe... |
| CVE-2024-48027 | CRITICAL | 9.9 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-f... |
| CVE-2024-48026 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection... |
| CVE-2024-47649 | CRITICAL | 9.1 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: ... |
| CVE-2024-47645 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar... |
| CVE-2024-47637 | HIGH | 8.8 | 0.6% | Oct 16, 2024 | Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.Th... |
| CVE-2024-47351 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxS... |
| CVE-2024-22034 | MEDIUM | 5.5 | 0.2% | Oct 16, 2024 | Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker t... |
| CVE-2024-22033 | MEDIUM | 6.3 | 0.9% | Oct 16, 2024 | The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide... |
| CVE-2024-22032 | HIGH | 7.1 | 0.4% | Oct 16, 2024 | A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption confi... |
| CVE-2024-22030 | HIGH | 8 | 0.4% | Oct 16, 2024 | A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-m... |
| CVE-2024-22029 | HIGH | 7.8 | 0.2% | Oct 16, 2024 | Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalat... |
| CVE-2024-49271 | HIGH | 7.2 | 1.1% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Ad... |
| CVE-2024-49257 | CRITICAL | 10 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Uplo... |
| CVE-2024-49247 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-re... |
| CVE-2024-48042 | CRITICAL | 9.1 | 1.1% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows ... |
| CVE-2024-10024 | HIGH | 8.8 | 0.6% | Oct 16, 2024 | A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. This ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now