2024 CVE Vulnerabilities
39,224 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45490 | HIGH | 7.5 | 1.7% | Aug 30, 2024 | An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. |
| CVE-2024-2881 | HIGH | 8.8 | 0.5% | Aug 30, 2024 | Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6... |
| CVE-2024-1545 | HIGH | 8.8 | 0.5% | Aug 29, 2024 | Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on... |
| CVE-2024-6672 | HIGH | 8.8 | 0.7% | Aug 29, 2024 | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged ... |
| CVE-2024-45302 | HIGH | 7.8 | 0.3% | Aug 29, 2024 | RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header valu... |
| CVE-2024-34019 | HIGH | 7.3 | 0.1% | Aug 29, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy ... |
| CVE-2024-34017 | HIGH | 7.3 | 0.1% | Aug 29, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy ... |
| CVE-2024-43804 | HIGH | 8.8 | 2.5% | Aug 29, 2024 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerabi... |
| CVE-2024-41964 | HIGH | 8.1 | 0.4% | Aug 29, 2024 | Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users o... |
| CVE-2024-35133 | HIGH | 8.2 | 1.6% | Aug 29, 2024 | IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct ph... |
| CVE-2024-43957 | HIGH | 8.8 | 0.6% | Aug 29, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated ... |
| CVE-2024-43955 | HIGH | 7.5 | 0.6% | Aug 29, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows Fil... |
| CVE-2024-43943 | HIGH | 8.8 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ... |
| CVE-2024-43942 | HIGH | 8.8 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ... |
| CVE-2024-39658 | HIGH | 7.2 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking Syst... |
| CVE-2024-39638 | HIGH | 8.8 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registr... |
| CVE-2024-39620 | HIGH | 8.8 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio Listi... |
| CVE-2024-38793 | HIGH | 8.8 | 1.2% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Re... |
| CVE-2024-38693 | HIGH | 7.2 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Fro... |
| CVE-2024-8297 | HIGH | 7.5 | 0.5% | Aug 29, 2024 | A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. A... |
| CVE-2024-3679 | HIGH | 7.5 | 0.4% | Aug 29, 2024 | The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all version... |
| CVE-2024-2541 | HIGH | 7.5 | 0.6% | Aug 29, 2024 | The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2024-7856 | HIGH | 8.1 | 18.8% | Aug 29, 2024 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized... |
| CVE-2024-7607 | HIGH | 8.8 | 0.5% | Aug 29, 2024 | The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all vers... |
| CVE-2024-5623 | HIGH | 7.8 | 0.2% | Aug 29, 2024 | An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now