2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8557 | HIGH | 7.5 | 0.5% | Sep 7, 2024 | A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affect... |
| CVE-2024-40681 | HIGH | 8.8 | 0.5% | Sep 7, 2024 | IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically define... |
| CVE-2024-37068 | HIGH | 7.5 | 0.2% | Sep 7, 2024 | IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms t... |
| CVE-2024-8523 | HIGH | 7.2 | 1.0% | Sep 7, 2024 | A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatD... |
| CVE-2024-45498 | HIGH | 8.8 | 1.2% | Sep 7, 2024 | Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an ... |
| CVE-2024-45034 | HIGH | 8.8 | 1.7% | Sep 7, 2024 | Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG fold... |
| CVE-2024-44845 | HIGH | 8.8 | 2.0% | Sep 6, 2024 | DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value para... |
| CVE-2024-44844 | HIGH | 8.8 | 1.9% | Sep 6, 2024 | DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name param... |
| CVE-2024-34158 | HIGH | 7.5 | 1.0% | Sep 6, 2024 | Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion. |
| CVE-2024-34156 | HIGH | 7.5 | 1.1% | Sep 6, 2024 | Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. T... |
| CVE-2024-7652 | HIGH | 7.5 | 0.7% | Sep 6, 2024 | An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially... |
| CVE-2024-38642 | HIGH | 7.8 | 0.1% | Sep 6, 2024 | An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability co... |
| CVE-2024-38641 | HIGH | 7.8 | 0.5% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2024-32763 | HIGH | 8.8 | 0.6% | Sep 6, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-21898 | HIGH | 8.8 | 1.2% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2024-8509 | HIGH | 7.5 | 0.6% | Sep 6, 2024 | A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to e... |
| CVE-2024-45294 | HIGH | 8.6 | 1.0% | Sep 6, 2024 | The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator)... |
| CVE-2024-44408 | HIGH | 7.5 | 0.6% | Sep 6, 2024 | D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration... |
| CVE-2024-8428 | HIGH | 8.8 | 0.5% | Sep 6, 2024 | The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Di... |
| CVE-2024-6445 | HIGH | 7.5 | 0.6% | Sep 6, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology Dat... |
| CVE-2024-44739 | HIGH | 8.8 | 0.5% | Sep 6, 2024 | Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=. |
| CVE-2024-1744 | HIGH | 7.5 | 0.4% | Sep 6, 2024 | Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allow... |
| CVE-2024-7349 | HIGH | 7.2 | 0.5% | Sep 6, 2024 | The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injectio... |
| CVE-2024-39585 | HIGH | 8.1 | 0.3% | Sep 6, 2024 | Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Pass... |
| CVE-2024-38486 | HIGH | 8.8 | 1.2% | Sep 6, 2024 | Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralizati... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now