2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46937 | HIGH | 7.5 | 0.5% | Sep 16, 2024 | An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Sec... |
| CVE-2024-46424 | HIGH | 7.5 | 0.6% | Sep 16, 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which ... |
| CVE-2024-45696 | HIGH | 8.8 | 0.6% | Sep 16, 2024 | Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, ... |
| CVE-2024-39613 | HIGH | 7.8 | 0.3% | Sep 16, 2024 | Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows ... |
| CVE-2024-8779 | HIGH | 8.8 | 0.5% | Sep 16, 2024 | OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowi... |
| CVE-2024-8777 | HIGH | 7.5 | 0.5% | Sep 16, 2024 | OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read ar... |
| CVE-2024-46943 | HIGH | 7.5 | 0.6% | Sep 15, 2024 | An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue contr... |
| CVE-2024-8876 | HIGH | 7.5 | 0.8% | Sep 15, 2024 | A vulnerability, which was classified as problematic, has been found in xiaohe4966 TpMeCMS up to 1.3.3.1. Affected by th... |
| CVE-2024-46938 | HIGH | 7.5 | 46.1% | Sep 15, 2024 | An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 ... |
| CVE-2024-8869 | HIGH | 8.1 | 1.7% | Sep 15, 2024 | A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The ... |
| CVE-2024-8864 | HIGH | 8.8 | 0.8% | Sep 15, 2024 | A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical. Affected by this vulnerabi... |
| CVE-2024-6482 | HIGH | 8.8 | 0.5% | Sep 14, 2024 | The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ... |
| CVE-2024-8669 | HIGH | 7.2 | 16.7% | Sep 14, 2024 | The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' ... |
| CVE-2024-8479 | HIGH | 7.3 | 0.6% | Sep 14, 2024 | The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This ... |
| CVE-2024-8246 | HIGH | 8.8 | 0.4% | Sep 14, 2024 | The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p... |
| CVE-2024-8271 | HIGH | 7.3 | 0.7% | Sep 14, 2024 | The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode e... |
| CVE-2024-44095 | HIGH | 7.8 | 0.1% | Sep 13, 2024 | In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This co... |
| CVE-2024-44094 | HIGH | 7.8 | 0.1% | Sep 13, 2024 | In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This... |
| CVE-2024-44093 | HIGH | 7.8 | 0.1% | Sep 13, 2024 | In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This... |
| CVE-2024-44092 | HIGH | 7.8 | 0.1% | Sep 13, 2024 | There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could l... |
| CVE-2024-29779 | HIGH | 7.8 | 0.1% | Sep 13, 2024 | there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privile... |
| CVE-2024-8784 | HIGH | 8.8 | 0.5% | Sep 13, 2024 | A vulnerability classified as critical was found in QDocs Smart School Management System 7.0.0. Affected by this vulnera... |
| CVE-2024-8281 | HIGH | 7.2 | 1.0% | Sep 13, 2024 | An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil... |
| CVE-2024-8280 | HIGH | 7.2 | 1.0% | Sep 13, 2024 | An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil... |
| CVE-2024-8279 | HIGH | 7.2 | 1.1% | Sep 13, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now