2024 CVE Vulnerabilities
39,224 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5622 | HIGH | 7.8 | 0.2% | Aug 29, 2024 | An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may... |
| CVE-2024-43700 | HIGH | 7.8 | 0.3% | Aug 29, 2024 | xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-ba... |
| CVE-2024-45436 | HIGH | 7.5 | 2.6% | Aug 29, 2024 | extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent direct... |
| CVE-2024-8198 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the ... |
| CVE-2024-8194 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2024-8193 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the ... |
| CVE-2024-45059 | HIGH | 8.8 | 0.7% | Aug 28, 2024 | i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators... |
| CVE-2024-45058 | HIGH | 8.1 | 1.4% | Aug 28, 2024 | i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators... |
| CVE-2024-44760 | HIGH | 7.5 | 0.5% | Aug 28, 2024 | Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0... |
| CVE-2024-42793 | HIGH | 8 | 0.2% | Aug 28, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted requ... |
| CVE-2024-41236 | HIGH | 7.2 | 0.4% | Aug 28, 2024 | A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an... |
| CVE-2024-7745 | HIGH | 8.1 | 0.4% | Aug 28, 2024 | In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Tra... |
| CVE-2024-20478 | HIGH | 7.2 | 0.7% | Aug 28, 2024 | A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco... |
| CVE-2024-20446 | HIGH | 8.6 | 0.8% | Aug 28, 2024 | A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cau... |
| CVE-2024-20286 | HIGH | 8.8 | 0.2% | Aug 28, 2024 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at... |
| CVE-2024-20285 | HIGH | 8.8 | 0.2% | Aug 28, 2024 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at... |
| CVE-2024-20284 | HIGH | 8.8 | 0.2% | Aug 28, 2024 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at... |
| CVE-2024-5546 | HIGH | 8.8 | 3.0% | Aug 28, 2024 | Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affect... |
| CVE-2024-6311 | HIGH | 7.2 | 0.9% | Aug 28, 2024 | The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in... |
| CVE-2024-4556 | HIGH | 7.5 | 0.4% | Aug 28, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Ma... |
| CVE-2024-4555 | HIGH | 7.5 | 0.3% | Aug 28, 2024 | Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specif... |
| CVE-2024-45346 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend M... |
| CVE-2024-39584 | HIGH | 8.2 | 0.2% | Aug 28, 2024 | Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with lo... |
| CVE-2024-8231 | HIGH | 8.8 | 1.2% | Aug 28, 2024 | A vulnerability classified as critical has been found in Tenda O6 1.0.0.7(2054). Affected is the function fromVirtualSet... |
| CVE-2024-45049 | HIGH | 7.5 | 0.6% | Aug 27, 2024 | Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now