2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45981 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via u... |
| CVE-2024-45980 | HIGH | 8.8 | 0.4% | Sep 26, 2024 | A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user inte... |
| CVE-2024-45979 | HIGH | 8.8 | 0.4% | Sep 26, 2024 | A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via us... |
| CVE-2024-44860 | HIGH | 7.5 | 0.5% | Sep 26, 2024 | An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access s... |
| CVE-2024-37125 | HIGH | 7.5 | 0.4% | Sep 26, 2024 | Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consum... |
| CVE-2024-43191 | HIGH | 8.8 | 0.8% | Sep 26, 2024 | IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specia... |
| CVE-2024-41605 | HIGH | 8.4 | 0.2% | Sep 26, 2024 | In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an updat... |
| CVE-2024-30134 | HIGH | 7.5 | 0.2% | Sep 26, 2024 | The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Un... |
| CVE-2024-46330 | HIGH | 7.4 | 0.7% | Sep 26, 2024 | VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun ... |
| CVE-2024-46329 | HIGH | 8 | 0.8% | Sep 26, 2024 | VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object. |
| CVE-2024-46328 | HIGH | 8 | 0.2% | Sep 26, 2024 | VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts,... |
| CVE-2024-7107 | HIGH | 7.5 | 0.3% | Sep 26, 2024 | Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath all... |
| CVE-2024-8704 | HIGH | 7.2 | 0.9% | Sep 26, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, a... |
| CVE-2024-8126 | HIGH | 8.8 | 0.9% | Sep 26, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php'... |
| CVE-2024-9199 | HIGH | 7.5 | 0.3% | Sep 26, 2024 | Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the ... |
| CVE-2024-47197 | HIGH | 7.5 | 0.8% | Sep 26, 2024 | Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in M... |
| CVE-2024-0132 | HIGH | 8.3 | 36.5% | Sep 26, 2024 | NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with de... |
| CVE-2024-47045 | HIGH | 7.8 | 0.1% | Sep 26, 2024 | Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, ... |
| CVE-2024-47330 | HIGH | 8.8 | 0.3% | Sep 26, 2024 | Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This i... |
| CVE-2024-8404 | HIGH | 7.8 | 0.4% | Sep 26, 2024 | An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print... |
| CVE-2024-47083 | HIGH | 7.5 | 1.5% | Sep 25, 2024 | Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior... |
| CVE-2024-47315 | HIGH | 8.8 | 0.2% | Sep 25, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= ... |
| CVE-2024-47305 | HIGH | 8.8 | 0.2% | Sep 25, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font use-any-font allows Cross Site Request Forge... |
| CVE-2024-47082 | HIGH | 8 | 0.2% | Sep 25, 2024 | Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as de... |
| CVE-2024-46489 | HIGH | 8.8 | 0.9% | Sep 25, 2024 | A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a cr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now