2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39440 | MEDIUM | 4.4 | 0.1% | Oct 9, 2024 | In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of ser... |
| CVE-2024-39439 | MEDIUM | 4.4 | 0.1% | Oct 9, 2024 | In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o... |
| CVE-2024-39438 | MEDIUM | 6.7 | 0.3% | Oct 9, 2024 | In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l... |
| CVE-2024-39437 | MEDIUM | 6.7 | 0.3% | Oct 9, 2024 | In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l... |
| CVE-2024-39436 | MEDIUM | 6.7 | 0.3% | Oct 9, 2024 | In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l... |
| CVE-2024-5968 | MEDIUM | 4.8 | 0.3% | Oct 9, 2024 | The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery set... |
| CVE-2024-42934 | MEDIUM | 5 | 0.4% | Oct 9, 2024 | OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting ... |
| CVE-2024-7963 | MEDIUM | 6.4 | 0.3% | Oct 9, 2024 | The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multi... |
| CVE-2024-36814 | MEDIUM | 4.9 | 0.8% | Oct 8, 2024 | An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary... |
| CVE-2024-47822 | MEDIUM | 4.2 | 0.3% | Oct 8, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are no... |
| CVE-2024-47780 | MEDIUM | 4.3 | 0.3% | Oct 8, 2024 | TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree wit... |
| CVE-2024-46410 | MEDIUM | 4.8 | 0.3% | Oct 8, 2024 | PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the... |
| CVE-2024-43614 | MEDIUM | 5.5 | 0.6% | Oct 8, 2024 | Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally. |
| CVE-2024-43612 | MEDIUM | 4.7 | 0.7% | Oct 8, 2024 | Power BI Report Server Spoofing Vulnerability |
| CVE-2024-43609 | MEDIUM | 6.5 | 2.0% | Oct 8, 2024 | Microsoft Office Spoofing Vulnerability |
| CVE-2024-43603 | MEDIUM | 5.5 | 0.8% | Oct 8, 2024 | Visual Studio Collector Service Denial of Service Vulnerability |
| CVE-2024-43585 | MEDIUM | 5.5 | 0.5% | Oct 8, 2024 | Code Integrity Guard Security Feature Bypass Vulnerability |
| CVE-2024-43561 | MEDIUM | 6.5 | 0.8% | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability |
| CVE-2024-43559 | MEDIUM | 6.5 | 0.8% | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability |
| CVE-2024-43558 | MEDIUM | 6.5 | 0.8% | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability |
| CVE-2024-43557 | MEDIUM | 6.5 | 0.8% | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability |
| CVE-2024-43555 | MEDIUM | 6.5 | 0.8% | Oct 8, 2024 | Windows Mobile Broadband Driver Denial of Service Vulnerability |
| CVE-2024-43554 | MEDIUM | 5.5 | 0.6% | Oct 8, 2024 | Windows Kernel-Mode Driver Information Disclosure Vulnerability |
| CVE-2024-43547 | MEDIUM | 5.9 | 0.7% | Oct 8, 2024 | Windows Kerberos Information Disclosure Vulnerability |
| CVE-2024-43546 | MEDIUM | 5.6 | 0.6% | Oct 8, 2024 | Windows Cryptographic Information Disclosure Vulnerability |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now