2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48307 | CRITICAL | 9.8 | 44.3% | Oct 31, 2024 | JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD... |
| CVE-2024-10556 | CRITICAL | 9.8 | 0.7% | Oct 31, 2024 | A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an ... |
| CVE-2024-51427 | CRITICAL | 9.8 | 0.6% | Oct 30, 2024 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an... |
| CVE-2024-51424 | CRITICAL | 9.8 | 0.6% | Oct 30, 2024 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an... |
| CVE-2024-48112 | CRITICAL | 9.8 | 0.9% | Oct 30, 2024 | A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to ... |
| CVE-2024-48202 | CRITICAL | 9.8 | 0.6% | Oct 30, 2024 | icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile. |
| CVE-2024-9419 | CRITICAL | 9.8 | 0.7% | Oct 30, 2024 | Client / Server PCs with the HP Smart Universal Printing Driver installed are potentially vulnerable to Remote Code Exec... |
| CVE-2024-10456 | CRITICAL | 9.8 | 17.7% | Oct 30, 2024 | Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that... |
| CVE-2024-50419 | CRITICAL | 9.8 | 0.3% | Oct 30, 2024 | Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploitin... |
| CVE-2024-51298 | CRITICAL | 9.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-31151 | CRITICAL | 9.8 | 0.7% | Oct 30, 2024 | A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthoriz... |
| CVE-2024-10525 | CRITICAL | 9.8 | 57.9% | Oct 30, 2024 | In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no rea... |
| CVE-2024-8512 | CRITICAL | 9.1 | 1.0% | Oct 30, 2024 | The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 v... |
| CVE-2024-50511 | CRITICAL | 9.9 | 0.5% | Oct 30, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in donimedia WP donimedia carousel wp-donimedia-carousel a... |
| CVE-2024-50510 | CRITICAL | 10 | 1.0% | Oct 30, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allow... |
| CVE-2024-50507 | CRITICAL | 9.8 | 1.0% | Oct 30, 2024 | Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This i... |
| CVE-2024-50503 | CRITICAL | 9.8 | 0.5% | Oct 30, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authen... |
| CVE-2024-10509 | CRITICAL | 9.8 | 0.8% | Oct 30, 2024 | A vulnerability, which was classified as critical, has been found in Codezips Online Institute Management System 1.0. Th... |
| CVE-2024-10507 | CRITICAL | 9.8 | 0.8% | Oct 30, 2024 | A vulnerability classified as critical was found in Codezips Free Exam Hall Seating Management System 1.0. This vulnerab... |
| CVE-2024-51568 | CRITICAL | 9.8 | 45.7% | Oct 29, 2024 | CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut... |
| CVE-2024-51567 | CRITICAL | 9.8 | 86.7% | Oct 29, 2024 | upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas... |
| CVE-2024-51378 | CRITICAL | 9.8 | 94.8% | Oct 29, 2024 | getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t... |
| CVE-2024-50428 | CRITICAL | 9.8 | 0.3% | Oct 29, 2024 | Missing Authorization vulnerability in mondula2016 Multi Step Form multi-step-form allows Exploiting Incorrectly Configu... |
| CVE-2024-48573 | CRITICAL | 9.8 | 1.0% | Oct 29, 2024 | A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and admin... |
| CVE-2024-48138 | CRITICAL | 9.8 | 0.8% | Oct 29, 2024 | A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now