2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9921 | CRITICAL | 9.8 | 0.7% | Oct 14, 2024 | The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote a... |
| CVE-2024-7099 | CRITICAL | 9.8 | 0.6% | Oct 13, 2024 | netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenat... |
| CVE-2024-9916 | CRITICAL | 9.8 | 73.7% | Oct 13, 2024 | A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some u... |
| CVE-2024-9047 | CRITICAL | 9.8 | 92.3% | Oct 12, 2024 | The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2... |
| CVE-2024-48772 | CRITICAL | 9.1 | 0.5% | Oct 11, 2024 | An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firm... |
| CVE-2024-48787 | CRITICAL | 9.1 | 0.5% | Oct 11, 2024 | An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information v... |
| CVE-2024-48786 | CRITICAL | 9.1 | 0.5% | Oct 11, 2024 | An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive info... |
| CVE-2024-48784 | CRITICAL | 9.8 | 0.5% | Oct 11, 2024 | An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive in... |
| CVE-2024-48778 | CRITICAL | 9.1 | 0.4% | Oct 11, 2024 | An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive... |
| CVE-2024-48769 | CRITICAL | 9.1 | 0.4% | Oct 11, 2024 | An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via t... |
| CVE-2024-48033 | CRITICAL | 9.8 | 0.6% | Oct 11, 2024 | Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Ob... |
| CVE-2024-47331 | CRITICAL | 9.8 | 0.6% | Oct 11, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi S... |
| CVE-2024-46532 | CRITICAL | 9.8 | 1.1% | Oct 11, 2024 | SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the... |
| CVE-2024-46088 | CRITICAL | 9.8 | 0.7% | Oct 11, 2024 | An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer... |
| CVE-2024-44730 | CRITICAL | 9.1 | 0.4% | Oct 11, 2024 | Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows atta... |
| CVE-2024-42640 | CRITICAL | 9.8 | 43.7% | Oct 11, 2024 | angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo... |
| CVE-2024-8755 | CRITICAL | 9.8 | 1.1% | Oct 11, 2024 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This ... |
| CVE-2024-47074 | CRITICAL | 9.8 | 0.6% | Oct 11, 2024 | DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source ... |
| CVE-2024-45402 | CRITICAL | 9.8 | 0.5% | Oct 11, 2024 | Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsi... |
| CVE-2024-9707 | CRITICAL | 9.8 | 9.1% | Oct 11, 2024 | The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca... |
| CVE-2024-9234 | CRITICAL | 9.8 | 10.4% | Oct 11, 2024 | The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerabl... |
| CVE-2024-21534 | CRITICAL | 9.8 | 9.1% | Oct 11, 2024 | All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati... |
| CVE-2024-9822 | CRITICAL | 9.8 | 0.9% | Oct 11, 2024 | The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5... |
| CVE-2024-9818 | CRITICAL | 9.8 | 0.6% | Oct 10, 2024 | A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affect... |
| CVE-2024-47871 | CRITICAL | 9.1 | 0.2% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communica... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now