2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43391 | HIGH | 8.1 | 0.5% | Sep 10, 2024 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, pa... |
| CVE-2024-43390 | HIGH | 8.1 | 0.5% | Sep 10, 2024 | A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding... |
| CVE-2024-43389 | HIGH | 8.1 | 0.5% | Sep 10, 2024 | A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY... |
| CVE-2024-43388 | HIGH | 8.8 | 0.6% | Sep 10, 2024 | A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validatio... |
| CVE-2024-43387 | HIGH | 8.8 | 0.6% | Sep 10, 2024 | A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in ... |
| CVE-2024-43386 | HIGH | 8.8 | 0.7% | Sep 10, 2024 | A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralizati... |
| CVE-2024-43385 | HIGH | 8.8 | 0.7% | Sep 10, 2024 | A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralizati... |
| CVE-2024-42427 | HIGH | 7.6 | 1.1% | Sep 10, 2024 | Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command ... |
| CVE-2024-6979 | HIGH | 7.5 | 0.3% | Sep 10, 2024 | Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-pri... |
| CVE-2024-8478 | HIGH | 7.3 | 0.6% | Sep 10, 2024 | The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up... |
| CVE-2024-8268 | HIGH | 8.8 | 0.7% | Sep 10, 2024 | The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering o... |
| CVE-2024-44725 | HIGH | 7.2 | 0.5% | Sep 9, 2024 | AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php. |
| CVE-2024-44724 | HIGH | 7.2 | 0.6% | Sep 9, 2024 | AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_a... |
| CVE-2024-27387 | HIGH | 7.8 | 0.2% | Sep 9, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. I... |
| CVE-2024-27383 | HIGH | 7.8 | 0.2% | Sep 9, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. I... |
| CVE-2024-7341 | HIGH | 7.1 | 0.8% | Sep 9, 2024 | A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie ... |
| CVE-2024-45411 | HIGH | 8.6 | 0.8% | Sep 9, 2024 | Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user... |
| CVE-2024-45296 | HIGH | 7.5 | 0.9% | Sep 9, 2024 | path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular exp... |
| CVE-2024-44335 | HIGH | 8.8 | 12.4% | Sep 9, 2024 | D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.... |
| CVE-2024-44334 | HIGH | 8.8 | 31.8% | Sep 9, 2024 | D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.... |
| CVE-2024-44333 | HIGH | 8.8 | 12.4% | Sep 9, 2024 | D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.... |
| CVE-2024-44720 | HIGH | 7.5 | 0.7% | Sep 9, 2024 | SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php. |
| CVE-2024-45041 | HIGH | 8.8 | 0.6% | Sep 9, 2024 | External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secr... |
| CVE-2024-44375 | HIGH | 7.5 | 0.7% | Sep 9, 2024 | D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function. |
| CVE-2024-6572 | HIGH | 7.4 | 0.3% | Sep 9, 2024 | Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now