2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42038 | HIGH | 7.8 | 0.1% | Aug 8, 2024 | Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerabilit... |
| CVE-2024-42036 | HIGH | 7.5 | 0.1% | Aug 8, 2024 | Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability... |
| CVE-2024-42035 | HIGH | 7.8 | 0.1% | Aug 8, 2024 | Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may a... |
| CVE-2024-42033 | HIGH | 7.1 | 0.1% | Aug 8, 2024 | Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability wi... |
| CVE-2024-42257 | HIGH | 7.8 | 0.2% | Aug 8, 2024 | In the Linux kernel, the following vulnerability has been resolved: ext4: use memtostr_pad() for s_volume_name As with... |
| CVE-2024-42031 | HIGH | 7.5 | 0.3% | Aug 8, 2024 | Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerabili... |
| CVE-2024-22069 | HIGH | 8.8 | 0.2% | Aug 8, 2024 | There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissi... |
| CVE-2024-7150 | HIGH | 8.8 | 0.6% | Aug 8, 2024 | The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id... |
| CVE-2024-6869 | HIGH | 7.1 | 0.3% | Aug 8, 2024 | The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2024-7492 | HIGH | 8.8 | 0.3% | Aug 8, 2024 | The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2024-7561 | HIGH | 8.8 | 0.7% | Aug 8, 2024 | The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via d... |
| CVE-2024-7560 | HIGH | 7.2 | 0.6% | Aug 8, 2024 | The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via... |
| CVE-2024-7486 | HIGH | 8.8 | 0.6% | Aug 8, 2024 | The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 v... |
| CVE-2024-38202 | HIGH | 7.3 | 1.7% | Aug 8, 2024 | Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabli... |
| CVE-2024-6893 | HIGH | 7.5 | 32.9% | Aug 8, 2024 | The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This all... |
| CVE-2024-6891 | HIGH | 8.8 | 1.0% | Aug 8, 2024 | Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login ... |
| CVE-2024-6890 | HIGH | 8.8 | 0.7% | Aug 7, 2024 | Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journ... |
| CVE-2024-6707 | HIGH | 8.8 | 1.0% | Aug 7, 2024 | Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traver... |
| CVE-2024-7143 | HIGH | 8.3 | 0.6% | Aug 7, 2024 | A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permission... |
| CVE-2024-7061 | HIGH | 7.8 | 0.2% | Aug 7, 2024 | Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta ... |
| CVE-2024-20451 | HIGH | 7.5 | 0.8% | Aug 7, 2024 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco... |
| CVE-2024-41309 | HIGH | 7.8 | 0.2% | Aug 7, 2024 | An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted termina... |
| CVE-2024-41308 | HIGH | 7.8 | 0.2% | Aug 7, 2024 | An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal enviro... |
| CVE-2024-42005 | HIGH | 7.3 | 1.2% | Aug 7, 2024 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on... |
| CVE-2024-41991 | HIGH | 7.5 | 1.0% | Aug 7, 2024 | An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now