2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43888 | HIGH | 7.8 | 0.2% | Aug 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: list_lru: fix UAF for memory cgroup The mem_cg... |
| CVE-2024-43444 | HIGH | 8.2 | 0.4% | Aug 26, 2024 | Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations reg... |
| CVE-2024-45241 | HIGH | 7.5 | 13.6% | Aug 26, 2024 | A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allow... |
| CVE-2024-41996 | HIGH | 7.5 | 1.1% | Aug 26, 2024 | Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is use... |
| CVE-2024-8147 | HIGH | 8.8 | 0.6% | Aug 25, 2024 | A vulnerability was found in code-projects Pharmacy Management System 1.0 and classified as critical. This issue affects... |
| CVE-2024-45240 | HIGH | 7.4 | 0.2% | Aug 24, 2024 | The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScri... |
| CVE-2024-45239 | HIGH | 7.5 | 0.5% | Aug 24, 2024 | An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca... |
| CVE-2024-45238 | HIGH | 7.5 | 0.3% | Aug 24, 2024 | An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca... |
| CVE-2024-45236 | HIGH | 7.5 | 0.5% | Aug 24, 2024 | An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca... |
| CVE-2024-45235 | HIGH | 7.5 | 0.3% | Aug 24, 2024 | An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca... |
| CVE-2024-45234 | HIGH | 7.5 | 0.5% | Aug 24, 2024 | An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor ca... |
| CVE-2024-7656 | HIGH | 8.8 | 0.8% | Aug 24, 2024 | The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi... |
| CVE-2024-7351 | HIGH | 7.2 | 0.6% | Aug 24, 2024 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.... |
| CVE-2024-7568 | HIGH | 8.1 | 0.3% | Aug 24, 2024 | The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,... |
| CVE-2024-45187 | HIGH | 8.8 | 0.5% | Aug 23, 2024 | Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high p... |
| CVE-2024-42845 | HIGH | 8 | 2.7% | Aug 23, 2024 | An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 al... |
| CVE-2024-44390 | HIGH | 8.8 | 0.3% | Aug 23, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset. |
| CVE-2024-39841 | HIGH | 8.8 | 1.1% | Aug 23, 2024 | A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, ... |
| CVE-2024-44386 | HIGH | 7.3 | 0.3% | Aug 23, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind. |
| CVE-2024-42756 | HIGH | 8.8 | 13.5% | Aug 23, 2024 | An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page |
| CVE-2024-42636 | HIGH | 7.2 | 0.9% | Aug 23, 2024 | DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath. |
| CVE-2024-42523 | HIGH | 7.2 | 0.5% | Aug 23, 2024 | publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData |
| CVE-2024-43791 | HIGH | 7.8 | 0.2% | Aug 23, 2024 | RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 ... |
| CVE-2024-42915 | HIGH | 8 | 0.4% | Aug 23, 2024 | A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token... |
| CVE-2024-42040 | HIGH | 8.1 | 0.6% | Aug 23, 2024 | Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now