2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6482 | HIGH | 8.8 | 0.5% | Sep 14, 2024 | The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ... |
| CVE-2024-8669 | HIGH | 7.2 | 16.7% | Sep 14, 2024 | The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' ... |
| CVE-2024-8479 | HIGH | 7.3 | 0.6% | Sep 14, 2024 | The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This ... |
| CVE-2024-8246 | HIGH | 8.8 | 0.4% | Sep 14, 2024 | The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p... |
| CVE-2024-8271 | HIGH | 7.3 | 0.7% | Sep 14, 2024 | The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-44095 | HIGH | 7.8 | 0.1% | Sep 13, 2024 | In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This co... |
| CVE-2024-44094 | HIGH | 7.8 | 0.1% | Sep 13, 2024 | In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This... |
| CVE-2024-44093 | HIGH | 7.8 | 0.1% | Sep 13, 2024 | In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This... |
| CVE-2024-44092 | HIGH | 7.8 | 0.1% | Sep 13, 2024 | There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could l... |
| CVE-2024-29779 | HIGH | 7.8 | 0.1% | Sep 13, 2024 | there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privile... |
| CVE-2024-8784 | HIGH | 8.8 | 0.5% | Sep 13, 2024 | A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnera... |
| CVE-2024-8281 | HIGH | 7.2 | 1.0% | Sep 13, 2024 | An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil... |
| CVE-2024-8280 | HIGH | 7.2 | 1.0% | Sep 13, 2024 | An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil... |
| CVE-2024-8279 | HIGH | 7.2 | 1.1% | Sep 13, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate... |
| CVE-2024-8278 | HIGH | 7.2 | 1.1% | Sep 13, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate... |
| CVE-2024-39924 | HIGH | 8.8 | 13.1% | Sep 13, 2024 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authen... |
| CVE-2024-6862 | HIGH | 8.1 | 0.3% | Sep 13, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive COR... |
| CVE-2024-45368 | HIGH | 8.8 | 0.3% | Sep 13, 2024 | The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response pro... |
| CVE-2024-43099 | HIGH | 8.8 | 0.3% | Sep 13, 2024 | The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions bet... |
| CVE-2024-31415 | HIGH | 8.1 | 0.1% | Sep 13, 2024 | The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes su... |
| CVE-2024-6587 | HIGH | 7.5 | 36.9% | Sep 13, 2024 | A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows ... |
| CVE-2024-42025 | HIGH | 7.8 | 0.8% | Sep 13, 2024 | A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (V... |
| CVE-2024-8242 | HIGH | 8.8 | 0.8% | Sep 13, 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uplo... |
| CVE-2024-7423 | HIGH | 8.8 | 0.3% | Sep 13, 2024 | The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1.... |
| CVE-2024-46713 | HIGH | 7.8 | 0.3% | Sep 13, 2024 | In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reporte... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now