2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50484 | CRITICAL | 10 | 0.5% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose... |
| CVE-2024-50482 | CRITICAL | 10 | 1.0% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-d... |
| CVE-2024-50480 | CRITICAL | 9.9 | 0.5% | Oct 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in azexo Marketing Automation by AZEXO marketing-automatio... |
| CVE-2024-45656 | CRITICAL | 9.8 | 0.4% | Oct 29, 2024 | IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, ... |
| CVE-2024-44217 | CRITICAL | 9.1 | 0.4% | Oct 28, 2024 | A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 1... |
| CVE-2024-50496 | CRITICAL | 10 | 0.5% | Oct 28, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for-wordpress allows Up... |
| CVE-2024-50495 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in nunomorgadinho Plugin Propagator wp-propagator allows U... |
| CVE-2024-48356 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php. |
| CVE-2024-40867 | CRITICAL | 9.6 | 0.7% | Oct 28, 2024 | A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPa... |
| CVE-2024-48465 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | The MRBS version 1.5.0 has an SQL injection vulnerability in the edit_entry_handler.php file, specifically in the rooms%... |
| CVE-2024-48357 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php. |
| CVE-2024-39205 | CRITICAL | 9.8 | 16.5% | Oct 28, 2024 | An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a ... |
| CVE-2024-10450 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as cri... |
| CVE-2024-10449 | CRITICAL | 9.8 | 1.4% | Oct 28, 2024 | A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects a... |
| CVE-2024-50497 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-50491 | CRITICAL | 9.8 | 1.0% | Oct 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME r... |
| CVE-2024-50483 | CRITICAL | 9.8 | 2.4% | Oct 28, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation.... |
| CVE-2024-50479 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocom... |
| CVE-2024-50478 | CRITICAL | 9.8 | 1.1% | Oct 28, 2024 | Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authe... |
| CVE-2024-50498 | CRITICAL | 9.8 | 53.6% | Oct 28, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console ... |
| CVE-2024-50492 | CRITICAL | 9.8 | 1.4% | Oct 28, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Cod... |
| CVE-2024-50489 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-wo... |
| CVE-2024-50487 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authe... |
| CVE-2024-50486 | CRITICAL | 9.8 | 0.5% | Oct 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allo... |
| CVE-2024-50477 | CRITICAL | 9.8 | 8.0% | Oct 28, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now