2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48027 | CRITICAL | 9.9 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-f... |
| CVE-2024-48026 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection... |
| CVE-2024-47649 | CRITICAL | 9.1 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: ... |
| CVE-2024-49257 | CRITICAL | 10 | 0.5% | Oct 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Uplo... |
| CVE-2024-49247 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-re... |
| CVE-2024-48042 | CRITICAL | 9.1 | 1.1% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows ... |
| CVE-2024-10022 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an u... |
| CVE-2024-10021 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by th... |
| CVE-2024-9061 | CRITICAL | 9.8 | 51.3% | Oct 16, 2024 | The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary sho... |
| CVE-2024-45216 | CRITICAL | 9.8 | 90.7% | Oct 16, 2024 | Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enable... |
| CVE-2024-10018 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any une... |
| CVE-2024-9634 | CRITICAL | 9.8 | 1.4% | Oct 16, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ... |
| CVE-2024-9305 | CRITICAL | 9.8 | 0.7% | Oct 16, 2024 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in... |
| CVE-2024-9105 | CRITICAL | 9.8 | 0.6% | Oct 16, 2024 | The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This... |
| CVE-2024-10004 | CRITICAL | 9.1 | 0.4% | Oct 15, 2024 | Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in so... |
| CVE-2024-9486 | CRITICAL | 9.8 | 2.2% | Oct 15, 2024 | A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enable... |
| CVE-2024-48782 | CRITICAL | 9.8 | 0.8% | Oct 15, 2024 | File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via ... |
| CVE-2024-48781 | CRITICAL | 9.8 | 0.7% | Oct 15, 2024 | An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary... |
| CVE-2024-48779 | CRITICAL | 9.8 | 0.8% | Oct 15, 2024 | An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary co... |
| CVE-2024-48411 | CRITICAL | 9.8 | 0.5% | Oct 15, 2024 | itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload... |
| CVE-2024-49195 | CRITICAL | 9.8 | 0.6% | Oct 15, 2024 | Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair |
| CVE-2024-21216 | CRITICAL | 9.8 | 0.7% | Oct 15, 2024 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2024-21172 | CRITICAL | 9 | 0.5% | Oct 15, 2024 | Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). ... |
| CVE-2024-48914 | CRITICAL | 9.1 | 59.8% | Oct 15, 2024 | Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's as... |
| CVE-2024-9986 | CRITICAL | 9.8 | 0.8% | Oct 15, 2024 | A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now