2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43969 | HIGH | 7.6 | 0.4% | Sep 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spi... |
| CVE-2024-46982 | HIGH | 7.5 | 58.8% | Sep 17, 2024 | Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible... |
| CVE-2024-8957 | HIGH | 7.2 | 82.0% | Sep 17, 2024 | PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not su... |
| CVE-2024-8905 | HIGH | 8.8 | 0.5% | Sep 17, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially expl... |
| CVE-2024-8904 | HIGH | 8.8 | 0.5% | Sep 17, 2024 | Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-45398 | HIGH | 8.8 | 0.5% | Sep 17, 2024 | Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious ... |
| CVE-2024-8949 | HIGH | 8.8 | 0.7% | Sep 17, 2024 | A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown... |
| CVE-2024-8948 | HIGH | 7.5 | 1.0% | Sep 17, 2024 | A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function m... |
| CVE-2024-8947 | HIGH | 8.1 | 1.0% | Sep 17, 2024 | A vulnerability was found in MicroPython 1.22.2. It has been declared as critical. Affected by this vulnerability is an ... |
| CVE-2024-8946 | HIGH | 7.5 | 1.0% | Sep 17, 2024 | A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umo... |
| CVE-2024-8900 | HIGH | 7.5 | 0.4% | Sep 17, 2024 | An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigation... |
| CVE-2024-43460 | HIGH | 8.8 | 0.7% | Sep 17, 2024 | Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacke... |
| CVE-2024-8945 | HIGH | 8.8 | 14.5% | Sep 17, 2024 | A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulner... |
| CVE-2024-42503 | HIGH | 7.2 | 1.5% | Sep 17, 2024 | Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitatio... |
| CVE-2024-42502 | HIGH | 7.2 | 1.8% | Sep 17, 2024 | Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of t... |
| CVE-2024-42501 | HIGH | 7.2 | 1.2% | Sep 17, 2024 | An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability all... |
| CVE-2024-8768 | HIGH | 7.5 | 0.7% | Sep 17, 2024 | A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, res... |
| CVE-2024-7788 | HIGH | 7.8 | 0.2% | Sep 17, 2024 | Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows ... |
| CVE-2024-47049 | HIGH | 8.2 | 0.6% | Sep 17, 2024 | The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URL... |
| CVE-2024-47047 | HIGH | 7.5 | 0.5% | Sep 17, 2024 | An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of ... |
| CVE-2024-22303 | HIGH | 8.8 | 0.4% | Sep 17, 2024 | Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez:... |
| CVE-2024-21743 | HIGH | 8.8 | 0.4% | Sep 17, 2024 | Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez L... |
| CVE-2024-46362 | HIGH | 8.8 | 0.3% | Sep 17, 2024 | FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana... |
| CVE-2024-46085 | HIGH | 8.8 | 0.2% | Sep 17, 2024 | FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana... |
| CVE-2024-5998 | HIGH | 7.8 | 0.4% | Sep 17, 2024 | A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now