2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43247 | HIGH | 8.8 | 0.4% | Aug 19, 2024 | Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by AC... |
| CVE-2024-43401 | HIGH | 8 | 0.6% | Aug 19, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without ... |
| CVE-2024-43232 | HIGH | 8.5 | 0.5% | Aug 19, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essent... |
| CVE-2024-43221 | HIGH | 8.5 | 0.5% | Aug 19, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetGridBuilde... |
| CVE-2024-42657 | HIGH | 7.5 | 0.5% | Aug 19, 2024 | An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information v... |
| CVE-2024-32927 | HIGH | 7.8 | 0.1% | Aug 19, 2024 | In sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to l... |
| CVE-2024-6348 | HIGH | 7.5 | 0.4% | Aug 19, 2024 | Predictable seed generation in the security access mechanism of UDS in the Blind Spot Protection Sensor ECU in Nissan Al... |
| CVE-2024-42633 | HIGH | 8.8 | 2.1% | Aug 19, 2024 | A Command Injection vulnerability exists in the do_upgrade_post function of the httpd binary in Linksys E1500 v1.0.06.00... |
| CVE-2024-43380 | HIGH | 7.5 | 0.8% | Aug 19, 2024 | fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5... |
| CVE-2024-6451 | HIGH | 7.2 | 0.8% | Aug 19, 2024 | AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before... |
| CVE-2024-44083 | HIGH | 7.5 | 1.4% | Aug 19, 2024 | ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump... |
| CVE-2024-44073 | HIGH | 7.5 | 0.6% | Aug 19, 2024 | The Miniscript (aka rust-miniscript) library before 12.2.0 for Rust allows stack consumption because it does not properl... |
| CVE-2024-44070 | HIGH | 7.5 | 0.6% | Aug 19, 2024 | An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual rem... |
| CVE-2024-44069 | HIGH | 7.5 | 0.5% | Aug 19, 2024 | Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dash... |
| CVE-2024-44067 | HIGH | 8.4 | 0.2% | Aug 19, 2024 | The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions tha... |
| CVE-2024-7917 | HIGH | 7.2 | 0.6% | Aug 18, 2024 | A vulnerability, which was classified as critical, has been found in DouPHP 1.7 Release 20220822. Affected by this issue... |
| CVE-2024-43315 | HIGH | 7.5 | 0.4% | Aug 18, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Ch... |
| CVE-2024-43288 | HIGH | 8.1 | 0.3% | Aug 18, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo F... |
| CVE-2024-43286 | HIGH | 8.8 | 0.5% | Aug 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly SEO Plugi... |
| CVE-2024-43282 | HIGH | 7.2 | 0.4% | Aug 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS.... |
| CVE-2024-43279 | HIGH | 7.1 | 0.3% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant N... |
| CVE-2024-43266 | HIGH | 8.8 | 0.4% | Aug 18, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal.This issue aff... |
| CVE-2024-43246 | HIGH | 7.1 | 0.3% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeon ... |
| CVE-2024-43244 | HIGH | 7.1 | 0.3% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in favethemes ... |
| CVE-2024-43241 | HIGH | 7.1 | 0.3% | Aug 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now