2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39638 | HIGH | 8.8 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roundup WP Registr... |
| CVE-2024-39620 | HIGH | 8.8 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio Listi... |
| CVE-2024-38793 | HIGH | 8.8 | 1.2% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Re... |
| CVE-2024-38693 | HIGH | 7.2 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP User Fro... |
| CVE-2024-8297 | HIGH | 7.5 | 0.5% | Aug 29, 2024 | A vulnerability was found in kitsada8621 Digital Library Management System 1.0. It has been classified as problematic. A... |
| CVE-2024-3679 | HIGH | 7.5 | 0.4% | Aug 29, 2024 | The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all version... |
| CVE-2024-2541 | HIGH | 7.5 | 0.6% | Aug 29, 2024 | The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2024-7856 | HIGH | 8.1 | 18.8% | Aug 29, 2024 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized... |
| CVE-2024-7607 | HIGH | 8.8 | 0.5% | Aug 29, 2024 | The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all vers... |
| CVE-2024-5623 | HIGH | 7.8 | 0.2% | Aug 29, 2024 | An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get ... |
| CVE-2024-5622 | HIGH | 7.8 | 0.2% | Aug 29, 2024 | An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may... |
| CVE-2024-43700 | HIGH | 7.8 | 0.3% | Aug 29, 2024 | xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-ba... |
| CVE-2024-45436 | HIGH | 7.5 | 2.6% | Aug 29, 2024 | extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent direct... |
| CVE-2024-8198 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the ... |
| CVE-2024-8194 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2024-8193 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the ... |
| CVE-2024-45059 | HIGH | 8.8 | 0.7% | Aug 28, 2024 | i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators... |
| CVE-2024-45058 | HIGH | 8.1 | 1.4% | Aug 28, 2024 | i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators... |
| CVE-2024-44760 | HIGH | 7.5 | 0.5% | Aug 28, 2024 | Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0... |
| CVE-2024-42793 | HIGH | 8 | 0.2% | Aug 28, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted requ... |
| CVE-2024-41236 | HIGH | 7.2 | 0.4% | Aug 28, 2024 | A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an... |
| CVE-2024-7745 | HIGH | 8.1 | 0.4% | Aug 28, 2024 | In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Tra... |
| CVE-2024-20478 | HIGH | 7.2 | 0.7% | Aug 28, 2024 | A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco... |
| CVE-2024-20446 | HIGH | 8.6 | 0.8% | Aug 28, 2024 | A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cau... |
| CVE-2024-20286 | HIGH | 8.8 | 0.2% | Aug 28, 2024 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now