2024 CVE Vulnerabilities
39,222 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7714 | HIGH | 7.5 | 0.8% | Sep 27, 2024 | The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls ... |
| CVE-2024-7713 | HIGH | 7.5 | 0.3% | Sep 27, 2024 | The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, al... |
| CVE-2024-47076 | HIGH | 8.6 | 83.4% | Sep 26, 2024 | CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the for... |
| CVE-2024-40508 | HIGH | 7.3 | 0.7% | Sep 26, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-40507 | HIGH | 7.3 | 0.7% | Sep 26, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-40506 | HIGH | 7.3 | 0.7% | Sep 26, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-6769 | HIGH | 8.4 | 1.1% | Sep 26, 2024 | A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Win... |
| CVE-2024-7594 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_princip... |
| CVE-2024-47180 | HIGH | 8.8 | 1.0% | Sep 26, 2024 | Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-... |
| CVE-2024-47179 | HIGH | 8.8 | 0.7% | Sep 26, 2024 | RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Po... |
| CVE-2024-47169 | HIGH | 8.8 | 0.8% | Sep 26, 2024 | Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions p... |
| CVE-2024-47126 | HIGH | 8.8 | 0.2% | Sep 26, 2024 | The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random func... |
| CVE-2024-39577 | HIGH | 8.8 | 0.8% | Sep 26, 2024 | Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of ... |
| CVE-2024-45982 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user ... |
| CVE-2024-45981 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via u... |
| CVE-2024-45980 | HIGH | 8.8 | 0.4% | Sep 26, 2024 | A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user inte... |
| CVE-2024-45979 | HIGH | 8.8 | 0.4% | Sep 26, 2024 | A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via us... |
| CVE-2024-44860 | HIGH | 7.5 | 0.5% | Sep 26, 2024 | An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access s... |
| CVE-2024-37125 | HIGH | 7.5 | 0.4% | Sep 26, 2024 | Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consum... |
| CVE-2024-43191 | HIGH | 8.8 | 0.8% | Sep 26, 2024 | IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specia... |
| CVE-2024-41605 | HIGH | 8.4 | 0.2% | Sep 26, 2024 | In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an updat... |
| CVE-2024-30134 | HIGH | 7.5 | 0.2% | Sep 26, 2024 | The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Un... |
| CVE-2024-46330 | HIGH | 7.4 | 0.7% | Sep 26, 2024 | VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun ... |
| CVE-2024-46329 | HIGH | 8 | 0.8% | Sep 26, 2024 | VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object. |
| CVE-2024-46328 | HIGH | 8 | 0.2% | Sep 26, 2024 | VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts,... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now