2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38124 | CRITICAL | 9 | 1.2% | Oct 8, 2024 | Windows Netlogon Elevation of Privilege Vulnerability |
| CVE-2024-47010 | CRITICAL | 9.8 | 38.0% | Oct 8, 2024 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authenticatio... |
| CVE-2024-47009 | CRITICAL | 9.8 | 1.7% | Oct 8, 2024 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authenticatio... |
| CVE-2024-45918 | CRITICAL | 9.8 | 0.4% | Oct 8, 2024 | Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_g... |
| CVE-2024-44349 | CRITICAL | 9.8 | 5.6% | Oct 8, 2024 | A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute ar... |
| CVE-2024-3057 | CRITICAL | 9.8 | 0.4% | Oct 8, 2024 | A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation. |
| CVE-2024-8884 | CRITICAL | 9.8 | 0.6% | Oct 8, 2024 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of cr... |
| CVE-2024-8943 | CRITICAL | 9.8 | 3.0% | Oct 8, 2024 | The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. Thi... |
| CVE-2024-8911 | CRITICAL | 9.8 | 2.8% | Oct 8, 2024 | The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, ... |
| CVE-2024-47553 | CRITICAL | 9.9 | 0.8% | Oct 8, 2024 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not... |
| CVE-2024-41798 | CRITICAL | 9.8 | 0.5% | Oct 8, 2024 | A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN t... |
| CVE-2024-45874 | CRITICAL | 9.8 | 0.7% | Oct 7, 2024 | A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence ... |
| CVE-2024-45873 | CRITICAL | 9.8 | 0.7% | Oct 7, 2024 | A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persisten... |
| CVE-2024-47557 | CRITICAL | 9.8 | 0.5% | Oct 7, 2024 | Pre-Auth RCE via Path Traversal |
| CVE-2024-47556 | CRITICAL | 9.8 | 0.5% | Oct 7, 2024 | Pre-Auth RCE via Path Traversal |
| CVE-2024-46076 | CRITICAL | 9.8 | 0.5% | Oct 7, 2024 | RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabl... |
| CVE-2024-46446 | CRITICAL | 9.8 | 1.4% | Oct 7, 2024 | Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identi... |
| CVE-2024-33066 | CRITICAL | 9.8 | 0.6% | Oct 7, 2024 | Memory corruption while redirecting log file to any file location with any file name. |
| CVE-2024-20103 | CRITICAL | 9.8 | 0.3% | Oct 7, 2024 | In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote co... |
| CVE-2024-20101 | CRITICAL | 9.8 | 0.3% | Oct 7, 2024 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code... |
| CVE-2024-20100 | CRITICAL | 9.8 | 0.3% | Oct 7, 2024 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code... |
| CVE-2024-47350 | CRITICAL | 9.3 | 0.4% | Oct 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooC... |
| CVE-2024-45252 | CRITICAL | 9.8 | 1.0% | Oct 6, 2024 | Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
| CVE-2024-45251 | CRITICAL | 9.8 | 1.0% | Oct 6, 2024 | Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
| CVE-2024-45249 | CRITICAL | 9.8 | 0.4% | Oct 6, 2024 | Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now