2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8644 | HIGH | 7.5 | 0.3% | Sep 27, 2024 | Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipul... |
| CVE-2024-8609 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Infor... |
| CVE-2024-9136 | HIGH | 7.5 | 0.2% | Sep 27, 2024 | Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulner... |
| CVE-2024-47294 | HIGH | 7.5 | 0.2% | Sep 27, 2024 | Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of thi... |
| CVE-2024-47293 | HIGH | 7.5 | 0.2% | Sep 27, 2024 | Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2024-38861 | HIGH | 7.4 | 0.2% | Sep 27, 2024 | Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traff... |
| CVE-2024-39435 | HIGH | 7.8 | 0.1% | Sep 27, 2024 | In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of ... |
| CVE-2024-9029 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read... |
| CVE-2024-7400 | HIGH | 8.5 | 0.2% | Sep 27, 2024 | The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file... |
| CVE-2024-9130 | HIGH | 7.2 | 0.7% | Sep 27, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via... |
| CVE-2024-8922 | HIGH | 8.8 | 0.8% | Sep 27, 2024 | The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Inject... |
| CVE-2024-7714 | HIGH | 7.5 | 0.8% | Sep 27, 2024 | The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls ... |
| CVE-2024-7713 | HIGH | 7.5 | 0.3% | Sep 27, 2024 | The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, al... |
| CVE-2024-47076 | HIGH | 8.6 | 83.4% | Sep 26, 2024 | CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the for... |
| CVE-2024-40508 | HIGH | 7.3 | 0.7% | Sep 26, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-40507 | HIGH | 7.3 | 0.7% | Sep 26, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-40506 | HIGH | 7.3 | 0.7% | Sep 26, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-6769 | HIGH | 8.4 | 1.1% | Sep 26, 2024 | A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Win... |
| CVE-2024-7594 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_princip... |
| CVE-2024-47180 | HIGH | 8.8 | 1.0% | Sep 26, 2024 | Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-... |
| CVE-2024-47179 | HIGH | 8.8 | 0.7% | Sep 26, 2024 | RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Po... |
| CVE-2024-47169 | HIGH | 8.8 | 0.8% | Sep 26, 2024 | Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p... |
| CVE-2024-47126 | HIGH | 8.8 | 0.2% | Sep 26, 2024 | The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random func... |
| CVE-2024-39577 | HIGH | 8.8 | 0.8% | Sep 26, 2024 | Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of ... |
| CVE-2024-45982 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now