2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31489 | HIGH | 8.1 | 0.4% | Sep 10, 2024 | AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0... |
| CVE-2024-23185 | HIGH | 7.5 | 1.3% | Sep 10, 2024 | Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably size... |
| CVE-2024-44867 | HIGH | 7.5 | 1.0% | Sep 10, 2024 | phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php. |
| CVE-2024-37728 | HIGH | 7.5 | 1.9% | Sep 10, 2024 | Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 al... |
| CVE-2024-7770 | HIGH | 8.8 | 1.1% | Sep 10, 2024 | The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulner... |
| CVE-2024-43647 | HIGH | 8.7 | 0.6% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200... |
| CVE-2024-41170 | HIGH | 7.8 | 0.2% | Sep 10, 2024 | A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0015), Tecnomatix Plant S... |
| CVE-2024-37994 | HIGH | 7.1 | 0.3% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC R... |
| CVE-2024-37993 | HIGH | 7.5 | 0.4% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC R... |
| CVE-2024-37992 | HIGH | 7.5 | 0.4% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC R... |
| CVE-2024-8258 | HIGH | 7.8 | 0.4% | Sep 10, 2024 | Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306... |
| CVE-2024-7699 | HIGH | 8.8 | 0.8% | Sep 10, 2024 | An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special... |
| CVE-2024-43393 | HIGH | 8.1 | 0.5% | Sep 10, 2024 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, pa... |
| CVE-2024-43392 | HIGH | 8.1 | 0.5% | Sep 10, 2024 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, pa... |
| CVE-2024-43391 | HIGH | 8.1 | 0.5% | Sep 10, 2024 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, pa... |
| CVE-2024-43390 | HIGH | 8.1 | 0.5% | Sep 10, 2024 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding... |
| CVE-2024-43389 | HIGH | 8.1 | 0.5% | Sep 10, 2024 | A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY... |
| CVE-2024-43388 | HIGH | 8.8 | 0.6% | Sep 10, 2024 | A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validatio... |
| CVE-2024-43387 | HIGH | 8.8 | 0.6% | Sep 10, 2024 | A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in ... |
| CVE-2024-43386 | HIGH | 8.8 | 0.7% | Sep 10, 2024 | A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralizati... |
| CVE-2024-43385 | HIGH | 8.8 | 0.7% | Sep 10, 2024 | A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralizati... |
| CVE-2024-42427 | HIGH | 7.6 | 1.1% | Sep 10, 2024 | Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command ... |
| CVE-2024-6979 | HIGH | 7.5 | 0.3% | Sep 10, 2024 | Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-pri... |
| CVE-2024-8478 | HIGH | 7.3 | 0.6% | Sep 10, 2024 | The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up... |
| CVE-2024-8268 | HIGH | 8.8 | 0.7% | Sep 10, 2024 | The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now