2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7432 | HIGH | 8.8 | 0.6% | Oct 1, 2024 | The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 vi... |
| CVE-2024-21489 | HIGH | 8.2 | 0.6% | Oct 1, 2024 | Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to m... |
| CVE-2024-47295 | HIGH | 8.1 | 0.8% | Oct 1, 2024 | Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set ... |
| CVE-2024-8981 | HIGH | 7.1 | 0.5% | Oct 1, 2024 | The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query... |
| CVE-2024-47560 | HIGH | 7.8 | 0.2% | Oct 1, 2024 | RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is ex... |
| CVE-2024-7675 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A mali... |
| CVE-2024-7674 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer O... |
| CVE-2024-7673 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Ove... |
| CVE-2024-7672 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bou... |
| CVE-2024-7671 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Writ... |
| CVE-2024-7670 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. ... |
| CVE-2024-28813 | HIGH | 8.4 | 0.2% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management applicatio... |
| CVE-2024-28812 | HIGH | 8.8 | 0.3% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) w... |
| CVE-2024-46511 | HIGH | 7.5 | 0.2% | Sep 30, 2024 | LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attack... |
| CVE-2024-28809 | HIGH | 8.8 | 0.2% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update package... |
| CVE-2024-46549 | HIGH | 7.6 | 0.3% | Sep 30, 2024 | An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connecti... |
| CVE-2024-46510 | HIGH | 7.6 | 0.3% | Sep 30, 2024 | ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax inter... |
| CVE-2024-46313 | HIGH | 8 | 2.2% | Sep 30, 2024 | TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm. |
| CVE-2024-46280 | HIGH | 8.8 | 0.3% | Sep 30, 2024 | PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak c... |
| CVE-2024-45772 | HIGH | 8 | 0.6% | Sep 30, 2024 | Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replica... |
| CVE-2024-8458 | HIGH | 8.8 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CS... |
| CVE-2024-8454 | HIGH | 7.5 | 0.6% | Sep 30, 2024 | The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-... |
| CVE-2024-6394 | HIGH | 7.5 | 0.6% | Sep 30, 2024 | A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to un... |
| CVE-2024-8452 | HIGH | 7.5 | 0.2% | Sep 30, 2024 | Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption... |
| CVE-2024-8451 | HIGH | 7.5 | 0.5% | Sep 30, 2024 | Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated co... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now