2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9814 | CRITICAL | 9.8 | 0.7% | Oct 10, 2024 | A vulnerability, which was classified as critical, was found in Codezips Pharmacy Management System 1.0. Affected is an ... |
| CVE-2024-9487 | CRITICAL | 9.1 | 22.4% | Oct 10, 2024 | An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowe... |
| CVE-2024-47167 | CRITICAL | 9.8 | 0.5% | Oct 10, 2024 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Requ... |
| CVE-2024-9813 | CRITICAL | 9.8 | 0.7% | Oct 10, 2024 | A vulnerability, which was classified as critical, has been found in Codezips Pharmacy Management System 1.0. This issue... |
| CVE-2024-9812 | CRITICAL | 9.8 | 0.7% | Oct 10, 2024 | A vulnerability classified as critical was found in code-projects Crud Operation System 1.0. This vulnerability affects ... |
| CVE-2024-9811 | CRITICAL | 9.8 | 0.7% | Oct 10, 2024 | A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. This affects a... |
| CVE-2024-47636 | CRITICAL | 9.8 | 0.5% | Oct 10, 2024 | Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affe... |
| CVE-2024-9794 | CRITICAL | 9.8 | 0.6% | Oct 10, 2024 | A vulnerability, which was classified as critical, has been found in Codezips Online Shopping Portal 1.0. This issue aff... |
| CVE-2024-9793 | CRITICAL | 9.8 | 21.5% | Oct 10, 2024 | A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the funct... |
| CVE-2024-9201 | CRITICAL | 9.8 | 0.5% | Oct 10, 2024 | The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_o... |
| CVE-2024-45115 | CRITICAL | 9.8 | 1.1% | Oct 10, 2024 | Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication v... |
| CVE-2024-9796 | CRITICAL | 9.8 | 3.0% | Oct 10, 2024 | The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a... |
| CVE-2024-9518 | CRITICAL | 9.8 | 0.5% | Oct 10, 2024 | The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to ins... |
| CVE-2024-48949 | CRITICAL | 9.1 | 0.5% | Oct 10, 2024 | The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(s... |
| CVE-2024-47832 | CRITICAL | 9.8 | 0.4% | Oct 9, 2024 | ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass a... |
| CVE-2024-9465 | CRITICAL | 9.1 | 99.6% | Oct 9, 2024 | An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition ... |
| CVE-2024-45746 | CRITICAL | 9.8 | 0.8% | Oct 9, 2024 | An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a p... |
| CVE-2024-25825 | CRITICAL | 9.8 | 0.5% | Oct 9, 2024 | FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be ... |
| CVE-2024-9680 | CRITICAL | 9.8 | 23.2% | Oct 9, 2024 | An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli... |
| CVE-2024-45160 | CRITICAL | 9.1 | 0.5% | Oct 9, 2024 | Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 clien... |
| CVE-2024-32608 | CRITICAL | 9.8 | 0.7% | Oct 9, 2024 | HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer a... |
| CVE-2024-47823 | CRITICAL | 9.8 | 0.8% | Oct 8, 2024 | Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/li... |
| CVE-2024-43591 | CRITICAL | 9.1 | 1.6% | Oct 8, 2024 | Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability |
| CVE-2024-43488 | CRITICAL | 9.8 | 1.1% | Oct 8, 2024 | Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attac... |
| CVE-2024-43468 | CRITICAL | 9.8 | 60.7% | Oct 8, 2024 | Microsoft Configuration Manager Remote Code Execution Vulnerability |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now