2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44390 | HIGH | 8.8 | 0.3% | Aug 23, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset. |
| CVE-2024-39841 | HIGH | 8.8 | 1.1% | Aug 23, 2024 | A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, ... |
| CVE-2024-44386 | HIGH | 7.3 | 0.3% | Aug 23, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind. |
| CVE-2024-42756 | HIGH | 8.8 | 13.5% | Aug 23, 2024 | An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page |
| CVE-2024-42636 | HIGH | 7.2 | 0.9% | Aug 23, 2024 | DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath. |
| CVE-2024-42523 | HIGH | 7.2 | 0.5% | Aug 23, 2024 | publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData |
| CVE-2024-43791 | HIGH | 7.8 | 0.2% | Aug 23, 2024 | RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 ... |
| CVE-2024-42915 | HIGH | 8 | 0.4% | Aug 23, 2024 | A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token... |
| CVE-2024-42040 | HIGH | 8.1 | 0.6% | Aug 23, 2024 | Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today o... |
| CVE-2024-37311 | HIGH | 8.2 | 0.2% | Aug 23, 2024 | Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, ... |
| CVE-2024-5586 | HIGH | 8.8 | 5.2% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet loc... |
| CVE-2024-5556 | HIGH | 8.8 | 4.5% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports modu... |
| CVE-2024-5490 | HIGH | 8.8 | 4.0% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate re... |
| CVE-2024-5467 | HIGH | 8.8 | 4.5% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lock... |
| CVE-2024-5466 | HIGH | 8.8 | 6.9% | Aug 23, 2024 | Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the aut... |
| CVE-2024-36517 | HIGH | 8.8 | 5.3% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts modul... |
| CVE-2024-36516 | HIGH | 8.8 | 4.4% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. N... |
| CVE-2024-36515 | HIGH | 8.8 | 4.5% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. N... |
| CVE-2024-36514 | HIGH | 8.8 | 4.0% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary... |
| CVE-2024-43883 | HIGH | 7 | 0.2% | Aug 23, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new re... |
| CVE-2024-7986 | HIGH | 7.5 | 0.6% | Aug 23, 2024 | A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensiti... |
| CVE-2024-7258 | HIGH | 8.8 | 0.8% | Aug 23, 2024 | The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing cap... |
| CVE-2024-7559 | HIGH | 8.8 | 0.9% | Aug 23, 2024 | The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation an... |
| CVE-2024-43477 | HIGH | 7.5 | 1.0% | Aug 23, 2024 | Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated at... |
| CVE-2024-38210 | HIGH | 7.8 | 0.7% | Aug 22, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now