2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20433 | HIGH | 7.5 | 0.6% | Sep 25, 2024 | A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software coul... |
| CVE-2024-20350 | HIGH | 8.1 | 0.4% | Sep 25, 2024 | A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, r... |
| CVE-2024-44825 | HIGH | 7.5 | 0.9% | Sep 25, 2024 | Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attac... |
| CVE-2024-46461 | HIGH | 8 | 0.6% | Sep 25, 2024 | VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be trigge... |
| CVE-2024-43959 | HIGH | 7.1 | 0.3% | Sep 25, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testim... |
| CVE-2024-22893 | HIGH | 7.5 | 0.4% | Sep 25, 2024 | OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This ... |
| CVE-2024-22892 | HIGH | 7.5 | 0.2% | Sep 25, 2024 | OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords. |
| CVE-2024-8316 | HIGH | 7.8 | 0.2% | Sep 25, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an in... |
| CVE-2024-7679 | HIGH | 7.8 | 0.7% | Sep 25, 2024 | In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible throu... |
| CVE-2024-6594 | HIGH | 7.5 | 0.5% | Sep 25, 2024 | Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the ... |
| CVE-2024-7481 | HIGH | 8.8 | 0.3% | Sep 25, 2024 | Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe ... |
| CVE-2024-7479 | HIGH | 8.8 | 0.4% | Sep 25, 2024 | Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe comp... |
| CVE-2024-45817 | HIGH | 7.3 | 0.5% | Sep 25, 2024 | In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status regis... |
| CVE-2024-31146 | HIGH | 7.5 | 0.2% | Sep 25, 2024 | When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system ... |
| CVE-2024-31145 | HIGH | 7.5 | 0.2% | Sep 25, 2024 | Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reportin... |
| CVE-2024-8175 | HIGH | 7.5 | 0.6% | Sep 25, 2024 | An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS. |
| CVE-2024-8290 | HIGH | 8.8 | 0.6% | Sep 25, 2024 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is... |
| CVE-2024-8514 | HIGH | 7.2 | 1.0% | Sep 25, 2024 | The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up... |
| CVE-2024-7385 | HIGH | 7.2 | 1.3% | Sep 25, 2024 | The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all vers... |
| CVE-2024-8484 | HIGH | 7.5 | 3.6% | Sep 25, 2024 | The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-jso... |
| CVE-2024-8481 | HIGH | 7.3 | 0.6% | Sep 25, 2024 | The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an... |
| CVE-2024-8349 | HIGH | 7.2 | 1.1% | Sep 25, 2024 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i... |
| CVE-2024-9123 | HIGH | 8.8 | 0.4% | Sep 25, 2024 | Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds m... |
| CVE-2024-9122 | HIGH | 8.8 | 5.9% | Sep 25, 2024 | Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory a... |
| CVE-2024-9121 | HIGH | 8.8 | 0.5% | Sep 25, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perf... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now