2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39816 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2024-39775 | HIGH | 7.5 | 0.4% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read. |
| CVE-2024-38386 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2024-20089 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of serv... |
| CVE-2024-7717 | HIGH | 8.8 | 0.5% | Aug 31, 2024 | The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all ve... |
| CVE-2024-0110 | HIGH | 7.8 | 0.2% | Aug 31, 2024 | NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by pass... |
| CVE-2024-44945 | HIGH | 7.8 | 0.2% | Aug 31, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use ... |
| CVE-2024-7435 | HIGH | 8.8 | 0.7% | Aug 31, 2024 | The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via des... |
| CVE-2024-6586 | HIGH | 7.3 | 1.8% | Aug 30, 2024 | Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and s... |
| CVE-2024-38868 | HIGH | 8.3 | 0.8% | Aug 30, 2024 | Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.Thi... |
| CVE-2024-8344 | HIGH | 8.8 | 0.5% | Aug 30, 2024 | A vulnerability has been found in Campcodes Supplier Management System 1.0 and classified as critical. Affected by this ... |
| CVE-2024-6204 | HIGH | 8.1 | 2.0% | Aug 30, 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module. |
| CVE-2024-8342 | HIGH | 8.8 | 0.6% | Aug 30, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Petshop Management System 1.0. This ... |
| CVE-2024-44916 | HIGH | 7.2 | 1.3% | Aug 30, 2024 | Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are writt... |
| CVE-2024-8338 | HIGH | 8.8 | 0.5% | Aug 30, 2024 | A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability ... |
| CVE-2024-8334 | HIGH | 8.1 | 0.5% | Aug 30, 2024 | A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as p... |
| CVE-2024-8260 | HIGH | 7.3 | 0.3% | Aug 30, 2024 | A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability e... |
| CVE-2024-8252 | HIGH | 8.8 | 3.0% | Aug 30, 2024 | The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 ... |
| CVE-2024-8016 | HIGH | 7.2 | 0.7% | Aug 30, 2024 | The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,... |
| CVE-2024-2694 | HIGH | 8.8 | 0.6% | Aug 30, 2024 | The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via d... |
| CVE-2024-5784 | HIGH | 7.1 | 0.4% | Aug 30, 2024 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing ... |
| CVE-2024-8330 | HIGH | 8.8 | 0.5% | Aug 30, 2024 | 6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regula... |
| CVE-2024-8329 | HIGH | 8.8 | 0.6% | Aug 30, 2024 | 6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers wit... |
| CVE-2024-8327 | HIGH | 8.8 | 0.7% | Aug 30, 2024 | Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific p... |
| CVE-2024-45490 | HIGH | 7.5 | 1.7% | Aug 30, 2024 | An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now