2024 CVE Vulnerabilities
39,220 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8592 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted CATPART file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Memory Corrupti... |
| CVE-2024-8591 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted 3DM file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Heap-Based Buffer O... |
| CVE-2024-8590 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerabil... |
| CVE-2024-8589 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read v... |
| CVE-2024-8588 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read v... |
| CVE-2024-7992 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, can force a Sta... |
| CVE-2024-7991 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, may force an Ou... |
| CVE-2024-44080 | HIGH | 7.5 | 0.5% | Oct 29, 2024 | In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resul... |
| CVE-2024-10488 | HIGH | 8.8 | 0.5% | Oct 29, 2024 | Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-10487 | HIGH | 8.8 | 0.7% | Oct 29, 2024 | Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds m... |
| CVE-2024-8587 | HIGH | 7.8 | 0.2% | Oct 29, 2024 | A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Ov... |
| CVE-2024-50456 | HIGH | 8.8 | 0.3% | Oct 29, 2024 | Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce... |
| CVE-2024-50455 | HIGH | 8.8 | 0.4% | Oct 29, 2024 | Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce... |
| CVE-2024-48955 | HIGH | 8.1 | 0.6% | Oct 29, 2024 | Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functi... |
| CVE-2024-9990 | HIGH | 8.8 | 0.3% | Oct 29, 2024 | The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This... |
| CVE-2024-8924 | HIGH | 7.5 | 0.5% | Oct 29, 2024 | ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability... |
| CVE-2024-50466 | HIGH | 8.8 | 0.2% | Oct 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkm... |
| CVE-2024-7985 | HIGH | 8.8 | 2.2% | Oct 29, 2024 | The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due ... |
| CVE-2024-49769 | HIGH | 7.5 | 1.4% | Oct 29, 2024 | Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before ... |
| CVE-2024-7962 | HIGH | 7.5 | 0.8% | Oct 29, 2024 | An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validatio... |
| CVE-2024-7807 | HIGH | 7.5 | 0.6% | Oct 29, 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploadi... |
| CVE-2024-7783 | HIGH | 7.5 | 0.3% | Oct 29, 2024 | mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password,... |
| CVE-2024-7474 | HIGH | 8.1 | 0.5% | Oct 29, 2024 | In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view o... |
| CVE-2024-6674 | HIGH | 7.1 | 0.2% | Oct 29, 2024 | A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information suc... |
| CVE-2024-41153 | HIGH | 7.2 | 1.6% | Oct 29, 2024 | Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now