2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8418 | HIGH | 7.5 | 0.8% | Sep 4, 2024 | A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP ... |
| CVE-2024-8410 | HIGH | 7.5 | 0.7% | Sep 4, 2024 | A vulnerability classified as problematic was found in ABCD ABCD2 up to 2.2.0-beta-1. This vulnerability affects unknown... |
| CVE-2024-8409 | HIGH | 7.5 | 0.7% | Sep 4, 2024 | A vulnerability classified as problematic has been found in ABCD ABCD2 up to 2.2.0-beta-1. This affects an unknown part ... |
| CVE-2024-45506 | HIGH | 7.5 | 1.2% | Sep 4, 2024 | HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2... |
| CVE-2024-7834 | HIGH | 7.8 | 0.3% | Sep 4, 2024 | A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-... |
| CVE-2024-7870 | HIGH | 7.5 | 0.4% | Sep 4, 2024 | The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable ... |
| CVE-2024-45195 | HIGH | 7.5 | 100.0% | Sep 4, 2024 | Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Us... |
| CVE-2024-8102 | HIGH | 8.8 | 0.5% | Sep 4, 2024 | The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-34660 | HIGH | 7.8 | 0.2% | Sep 4, 2024 | Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary c... |
| CVE-2024-34658 | HIGH | 7.1 | 0.2% | Sep 4, 2024 | Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR. |
| CVE-2024-34656 | HIGH | 7.8 | 0.2% | Sep 4, 2024 | Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code. |
| CVE-2024-34638 | HIGH | 7.1 | 0.1% | Sep 4, 2024 | Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to del... |
| CVE-2024-39921 | HIGH | 7.5 | 0.4% | Sep 4, 2024 | Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF040... |
| CVE-2024-45450 | HIGH | 7.5 | 0.2% | Sep 4, 2024 | Permission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability ma... |
| CVE-2024-45442 | HIGH | 7.5 | 0.2% | Sep 4, 2024 | Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of ... |
| CVE-2024-45441 | HIGH | 7.5 | 0.2% | Sep 4, 2024 | Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will... |
| CVE-2024-42039 | HIGH | 7.5 | 0.2% | Sep 4, 2024 | Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect ser... |
| CVE-2024-41716 | HIGH | 8.1 | 0.4% | Sep 4, 2024 | Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exp... |
| CVE-2024-8362 | HIGH | 8.8 | 0.5% | Sep 3, 2024 | Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit hea... |
| CVE-2024-7970 | HIGH | 8.8 | 0.5% | Sep 3, 2024 | Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap... |
| CVE-2024-45394 | HIGH | 7.8 | 0.1% | Sep 3, 2024 | Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption... |
| CVE-2024-45391 | HIGH | 7.5 | 0.3% | Sep 3, 2024 | Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prio... |
| CVE-2024-41436 | HIGH | 7.5 | 0.6% | Sep 3, 2024 | ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl. |
| CVE-2024-41435 | HIGH | 7.5 | 0.5% | Sep 3, 2024 | YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter. |
| CVE-2024-42902 | HIGH | 8.8 | 1.0% | Sep 3, 2024 | An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now