2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6477 | HIGH | 7.5 | 0.6% | Aug 3, 2024 | The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could all... |
| CVE-2024-3056 | HIGH | 7.7 | 0.5% | Aug 2, 2024 | A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configur... |
| CVE-2024-38891 | HIGH | 7.5 | 0.5% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-42348 | HIGH | 8.6 | 0.6% | Aug 2, 2024 | FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and passw... |
| CVE-2024-28298 | HIGH | 8.8 | 0.5% | Aug 2, 2024 | SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands v... |
| CVE-2024-28297 | HIGH | 7.5 | 0.4% | Aug 2, 2024 | SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via ... |
| CVE-2024-22169 | HIGH | 7.1 | 0.3% | Aug 2, 2024 | WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow c... |
| CVE-2024-38885 | HIGH | 7.5 | 0.5% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-38884 | HIGH | 7.8 | 0.2% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-38881 | HIGH | 7.5 | 0.5% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-33896 | HIGH | 7.2 | 4.0% | Aug 2, 2024 | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due... |
| CVE-2024-33894 | HIGH | 8.8 | 0.8% | Aug 2, 2024 | Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3... |
| CVE-2024-33892 | HIGH | 7.5 | 0.4% | Aug 2, 2024 | Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s... |
| CVE-2024-41518 | HIGH | 7.5 | 0.7% | Aug 2, 2024 | An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allow... |
| CVE-2024-41310 | HIGH | 7.5 | 0.8% | Aug 2, 2024 | AndServer 2.1.12 is vulnerable to Directory Traversal. |
| CVE-2024-38890 | HIGH | 8.4 | 0.2% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later version... |
| CVE-2024-40721 | HIGH | 8.8 | 0.5% | Aug 2, 2024 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-... |
| CVE-2024-40720 | HIGH | 8.8 | 0.6% | Aug 2, 2024 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-... |
| CVE-2024-38877 | HIGH | 8.8 | 0.2% | Aug 2, 2024 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont... |
| CVE-2024-38876 | HIGH | 7.8 | 0.2% | Aug 2, 2024 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont... |
| CVE-2024-27181 | HIGH | 8.8 | 0.7% | Aug 2, 2024 | In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted ac... |
| CVE-2024-38776 | HIGH | 7.1 | 0.1% | Aug 2, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This i... |
| CVE-2024-3238 | HIGH | 8.8 | 0.4% | Aug 2, 2024 | The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2024-39392 | HIGH | 7.8 | 0.4% | Aug 2, 2024 | InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that c... |
| CVE-2024-7389 | HIGH | 7.5 | 0.7% | Aug 2, 2024 | The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now