2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20285 | HIGH | 8.8 | 0.2% | Aug 28, 2024 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at... |
| CVE-2024-20284 | HIGH | 8.8 | 0.2% | Aug 28, 2024 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at... |
| CVE-2024-5546 | HIGH | 8.8 | 3.0% | Aug 28, 2024 | Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affect... |
| CVE-2024-6311 | HIGH | 7.2 | 0.9% | Aug 28, 2024 | The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in... |
| CVE-2024-4556 | HIGH | 7.5 | 0.4% | Aug 28, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Ma... |
| CVE-2024-4555 | HIGH | 7.5 | 0.3% | Aug 28, 2024 | Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specif... |
| CVE-2024-45346 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend M... |
| CVE-2024-39584 | HIGH | 8.2 | 0.2% | Aug 28, 2024 | Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with lo... |
| CVE-2024-8231 | HIGH | 8.8 | 1.2% | Aug 28, 2024 | A vulnerability classified as critical has been found in Tenda O6 1.0.0.7(2054). Affected is the function fromVirtualSet... |
| CVE-2024-45049 | HIGH | 7.5 | 0.6% | Aug 27, 2024 | Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without... |
| CVE-2024-45038 | HIGH | 7.5 | 0.6% | Aug 27, 2024 | Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh net... |
| CVE-2024-5991 | HIGH | 7.5 | 0.6% | Aug 27, 2024 | In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and un... |
| CVE-2024-43783 | HIGH | 7.5 | 0.9% | Aug 27, 2024 | The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph th... |
| CVE-2024-43414 | HIGH | 7.5 | 1.0% | Aug 27, 2024 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slic... |
| CVE-2024-42851 | HIGH | 7.8 | 0.3% | Aug 27, 2024 | Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the p... |
| CVE-2024-45264 | HIGH | 8.8 | 0.5% | Aug 27, 2024 | A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote... |
| CVE-2024-44340 | HIGH | 8.8 | 1.8% | Aug 27, 2024 | D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_e... |
| CVE-2024-6632 | HIGH | 7.2 | 0.6% | Aug 27, 2024 | A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an ... |
| CVE-2024-8182 | HIGH | 7.5 | 13.9% | Aug 27, 2024 | An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of ... |
| CVE-2024-8181 | HIGH | 8.1 | 46.1% | Aug 27, 2024 | An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attac... |
| CVE-2024-4872 | HIGH | 8.8 | 0.5% | Aug 27, 2024 | A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an ... |
| CVE-2024-3982 | HIGH | 8.2 | 0.2% | Aug 27, 2024 | An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging suppor... |
| CVE-2024-3980 | HIGH | 8.8 | 0.6% | Aug 27, 2024 | The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that ... |
| CVE-2024-41176 | HIGH | 7.3 | 0.3% | Aug 27, 2024 | The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Ser... |
| CVE-2024-41174 | HIGH | 7.3 | 0.2% | Aug 27, 2024 | The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local att... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now