2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8338 | HIGH | 8.8 | 0.5% | Aug 30, 2024 | A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability ... |
| CVE-2024-8334 | HIGH | 8.1 | 0.5% | Aug 30, 2024 | A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as p... |
| CVE-2024-8260 | HIGH | 7.3 | 0.3% | Aug 30, 2024 | A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability e... |
| CVE-2024-8252 | HIGH | 8.8 | 3.0% | Aug 30, 2024 | The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 ... |
| CVE-2024-8016 | HIGH | 7.2 | 0.7% | Aug 30, 2024 | The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,... |
| CVE-2024-2694 | HIGH | 8.8 | 0.6% | Aug 30, 2024 | The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via d... |
| CVE-2024-5784 | HIGH | 7.1 | 0.4% | Aug 30, 2024 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing ... |
| CVE-2024-8330 | HIGH | 8.8 | 0.5% | Aug 30, 2024 | 6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regula... |
| CVE-2024-8329 | HIGH | 8.8 | 0.6% | Aug 30, 2024 | 6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers wit... |
| CVE-2024-8327 | HIGH | 8.8 | 0.7% | Aug 30, 2024 | Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific p... |
| CVE-2024-45490 | HIGH | 7.5 | 1.7% | Aug 30, 2024 | An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. |
| CVE-2024-2881 | HIGH | 8.8 | 0.5% | Aug 30, 2024 | Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6... |
| CVE-2024-1545 | HIGH | 8.8 | 0.5% | Aug 29, 2024 | Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on... |
| CVE-2024-6672 | HIGH | 8.8 | 0.7% | Aug 29, 2024 | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged ... |
| CVE-2024-45302 | HIGH | 7.8 | 0.3% | Aug 29, 2024 | RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header valu... |
| CVE-2024-34019 | HIGH | 7.3 | 0.1% | Aug 29, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy ... |
| CVE-2024-34017 | HIGH | 7.3 | 0.1% | Aug 29, 2024 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy ... |
| CVE-2024-43804 | HIGH | 8.8 | 2.5% | Aug 29, 2024 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerabi... |
| CVE-2024-41964 | HIGH | 8.1 | 0.4% | Aug 29, 2024 | Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users o... |
| CVE-2024-35133 | HIGH | 8.2 | 1.6% | Aug 29, 2024 | IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct ph... |
| CVE-2024-43957 | HIGH | 8.8 | 0.6% | Aug 29, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated ... |
| CVE-2024-43955 | HIGH | 7.5 | 0.6% | Aug 29, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows Fil... |
| CVE-2024-43943 | HIGH | 8.8 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ... |
| CVE-2024-43942 | HIGH | 8.8 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ... |
| CVE-2024-39658 | HIGH | 7.2 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking Syst... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now