2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48514 | CRITICAL | 9.8 | 1.0% | Oct 24, 2024 | php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is abl... |
| CVE-2024-46478 | CRITICAL | 9.8 | 0.7% | Oct 24, 2024 | HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. |
| CVE-2024-48548 | CRITICAL | 9.3 | 0.2% | Oct 24, 2024 | The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulne... |
| CVE-2024-48539 | CRITICAL | 9.8 | 0.3% | Oct 24, 2024 | Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism. |
| CVE-2024-44206 | CRITICAL | 9.3 | 0.5% | Oct 24, 2024 | An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.... |
| CVE-2024-10336 | CRITICAL | 9.8 | 0.6% | Oct 24, 2024 | A vulnerability was found in SourceCodeHero Clothes Recommendation System 1.0. It has been rated as critical. This issue... |
| CVE-2024-10335 | CRITICAL | 9.8 | 0.7% | Oct 24, 2024 | A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. ... |
| CVE-2024-48538 | CRITICAL | 9.8 | 0.5% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sen... |
| CVE-2024-49681 | CRITICAL | 9.3 | 1.1% | Oct 24, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com W... |
| CVE-2024-48963 | CRITICAL | 9.8 | 0.4% | Oct 23, 2024 | The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnera... |
| CVE-2024-20424 | CRITICAL | 9.9 | 0.9% | Oct 23, 2024 | A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl... |
| CVE-2024-20329 | CRITICAL | 9.9 | 1.2% | Oct 23, 2024 | A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, r... |
| CVE-2024-49671 | CRITICAL | 9.9 | 0.5% | Oct 23, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featu... |
| CVE-2024-49669 | CRITICAL | 9.9 | 0.5% | Oct 23, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Alexander De Ridder INK Official ink-official allows Up... |
| CVE-2024-49668 | CRITICAL | 10 | 1.5% | Oct 23, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows ... |
| CVE-2024-49658 | CRITICAL | 9.9 | 0.5% | Oct 23, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in ecomerciar Woocommerce Custom Profile Picture woo-custo... |
| CVE-2024-49653 | CRITICAL | 9.9 | 1.2% | Oct 23, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web ... |
| CVE-2024-49652 | CRITICAL | 9.9 | 0.5% | Oct 23, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-p... |
| CVE-2024-10293 | CRITICAL | 9.8 | 0.5% | Oct 23, 2024 | A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of... |
| CVE-2024-10292 | CRITICAL | 9.8 | 0.5% | Oct 23, 2024 | A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the fi... |
| CVE-2024-10291 | CRITICAL | 9.8 | 0.5% | Oct 23, 2024 | A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_Do... |
| CVE-2024-47903 | CRITICAL | 9.1 | 0.4% | Oct 23, 2024 | A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir... |
| CVE-2024-47902 | CRITICAL | 9.8 | 0.5% | Oct 23, 2024 | A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir... |
| CVE-2024-47901 | CRITICAL | 9.8 | 1.2% | Oct 23, 2024 | A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir... |
| CVE-2024-47575 | CRITICAL | 9.8 | 94.8% | Oct 23, 2024 | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now