2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3293 | HIGH | 8.8 | 1.4% | Apr 23, 2024 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtme... |
| CVE-2024-3177 | LOW | 2.7 | 2.2% | Apr 22, 2024 | A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable sec... |
| CVE-2024-32657 | MEDIUM | 5.4 | 0.5% | Apr 22, 2024 | Hydra is a Continuous Integration service for Nix based projects. Attackers can execute arbitrary code in the browser co... |
| CVE-2024-32656 | HIGH | 7.8 | 0.2% | Apr 22, 2024 | Ant Media Server is live streaming engine software. A local privilege escalation vulnerability in present in versions 2.... |
| CVE-2024-32653 | MEDIUM | 6.1 | 0.2% | Apr 22, 2024 | jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This ... |
| CVE-2024-32480 | HIGH | 7.2 | 20.3% | Apr 22, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Versions prior to 24.4.0 are vulnerable to S... |
| CVE-2024-32479 | MEDIUM | 5.4 | 34.1% | Apr 22, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper s... |
| CVE-2024-32461 | HIGH | 8.8 | 19.1% | Apr 22, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A SQL injection vulnerability in POST /searc... |
| CVE-2024-32460 | CRITICAL | 9.8 | 1.9% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI... |
| CVE-2024-32459 | CRITICAL | 9.8 | 3.8% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of... |
| CVE-2024-31036 | MEDIUM | 6.8 | 0.3% | Apr 22, 2024 | A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of ... |
| CVE-2024-32458 | CRITICAL | 9.8 | 2.0% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP pri... |
| CVE-2024-32394 | HIGH | 8.8 | 12.6% | Apr 22, 2024 | An issue in ruijie.com/cn RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 and RG-RSR10-01G-T(WA)-S RSR_3.0(1... |
| CVE-2024-32041 | CRITICAL | 9.8 | 1.9% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP pri... |
| CVE-2024-32040 | CRITICAL | 9.8 | 1.9% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP pri... |
| CVE-2024-32039 | CRITICAL | 9.8 | 2.3% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior ... |
| CVE-2024-29368 | MEDIUM | 6.5 | 0.8% | Apr 22, 2024 | An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extensio... |
| CVE-2024-27574 | CRITICAL | 9.1 | 0.6% | Apr 22, 2024 | SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive inform... |
| CVE-2024-4040 | CRITICAL | 10 | 99.5% | Apr 22, 2024 | A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms all... |
| CVE-2024-32405 | LOW | 2.6 | 0.5% | Apr 22, 2024 | Cross Site Scripting vulnerability in inducer relate before v.2024.1 allows a remote attacker to escalate privileges via... |
| CVE-2024-32399 | HIGH | 7.6 | 3.2% | Apr 22, 2024 | Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensi... |
| CVE-2024-32238 | CRITICAL | 9.8 | 53.2% | Apr 22, 2024 | H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse... |
| CVE-2024-32205 | — | — | — | Apr 22, 2024 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2024-32407 | HIGH | 8.8 | 1.1% | Apr 22, 2024 | An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to t... |
| CVE-2024-31545 | CRITICAL | 9.4 | 0.6% | Apr 22, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/ma... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now