2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31145 | HIGH | 7.5 | 0.2% | Sep 25, 2024 | Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reportin... |
| CVE-2024-8175 | HIGH | 7.5 | 0.6% | Sep 25, 2024 | An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS. |
| CVE-2024-8290 | HIGH | 8.8 | 0.6% | Sep 25, 2024 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is... |
| CVE-2024-8514 | HIGH | 7.2 | 1.0% | Sep 25, 2024 | The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up... |
| CVE-2024-7385 | HIGH | 7.2 | 1.3% | Sep 25, 2024 | The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all vers... |
| CVE-2024-8484 | HIGH | 7.5 | 3.6% | Sep 25, 2024 | The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-jso... |
| CVE-2024-8481 | HIGH | 7.3 | 0.6% | Sep 25, 2024 | The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an... |
| CVE-2024-8349 | HIGH | 7.2 | 1.1% | Sep 25, 2024 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i... |
| CVE-2024-9123 | HIGH | 8.8 | 0.4% | Sep 25, 2024 | Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds m... |
| CVE-2024-9122 | HIGH | 8.8 | 5.9% | Sep 25, 2024 | Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory a... |
| CVE-2024-9121 | HIGH | 8.8 | 0.5% | Sep 25, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perf... |
| CVE-2024-9120 | HIGH | 8.8 | 0.4% | Sep 25, 2024 | Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially explo... |
| CVE-2024-8942 | HIGH | 8.2 | 0.3% | Sep 25, 2024 | Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input vali... |
| CVE-2024-8914 | HIGH | 7.2 | 0.3% | Sep 25, 2024 | The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulner... |
| CVE-2024-8497 | HIGH | 8.7 | 0.6% | Sep 25, 2024 | Franklin Fueling Systems TS-550 EVO versions prior to 2.26.4.8967 possess a file that can be read arbitrarily that could... |
| CVE-2024-46936 | HIGH | 7.5 | 0.4% | Sep 25, 2024 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation i... |
| CVE-2024-46935 | HIGH | 7.5 | 0.6% | Sep 25, 2024 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers... |
| CVE-2024-46610 | HIGH | 7.5 | 0.4% | Sep 25, 2024 | An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including... |
| CVE-2024-46609 | HIGH | 7.5 | 0.7% | Sep 25, 2024 | An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticat... |
| CVE-2024-46607 | HIGH | 7.6 | 0.6% | Sep 25, 2024 | Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values a... |
| CVE-2024-45373 | HIGH | 8.8 | 0.5% | Sep 25, 2024 | Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator. |
| CVE-2024-39928 | HIGH | 7.5 | 0.5% | Sep 25, 2024 | In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the To... |
| CVE-2024-21545 | HIGH | 8.2 | 0.4% | Sep 25, 2024 | Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient saf... |
| CVE-2024-8623 | HIGH | 7.3 | 0.6% | Sep 24, 2024 | The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in al... |
| CVE-2024-8795 | HIGH | 8.8 | 0.3% | Sep 24, 2024 | The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now