2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8432 | MEDIUM | 4.3 | 0.4% | Sep 24, 2024 | The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2024-38269 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel ... |
| CVE-2024-38268 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG882... |
| CVE-2024-38267 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG88... |
| CVE-2024-38266 | MEDIUM | 4.9 | 0.4% | Sep 24, 2024 | An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG... |
| CVE-2024-7022 | MEDIUM | 4.3 | 0.3% | Sep 23, 2024 | Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memor... |
| CVE-2024-7020 | MEDIUM | 4.3 | 0.3% | Sep 23, 2024 | Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI... |
| CVE-2024-7019 | MEDIUM | 4.3 | 0.3% | Sep 23, 2024 | Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a use... |
| CVE-2024-8770 | MEDIUM | 6.1 | 0.3% | Sep 23, 2024 | A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server... |
| CVE-2024-44540 | MEDIUM | 6.6 | 0.2% | Sep 23, 2024 | Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command s... |
| CVE-2024-43201 | MEDIUM | 5.9 | 0.4% | Sep 23, 2024 | The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker... |
| CVE-2024-39843 | MEDIUM | 6.7 | 2.1% | Sep 23, 2024 | A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm... |
| CVE-2024-39342 | MEDIUM | 6.6 | 0.1% | Sep 23, 2024 | Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier use... |
| CVE-2024-39341 | MEDIUM | 5.9 | 0.2% | Sep 23, 2024 | Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and... |
| CVE-2024-9014 | MEDIUM | 6.5 | 9.7% | Sep 23, 2024 | pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows ... |
| CVE-2024-40441 | MEDIUM | 6.6 | 0.6% | Sep 23, 2024 | An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi... |
| CVE-2024-47069 | MEDIUM | 6.1 | 0.4% | Sep 23, 2024 | Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy set... |
| CVE-2024-47068 | MEDIUM | 6.1 | 0.7% | Sep 23, 2024 | Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobber... |
| CVE-2024-23972 | MEDIUM | 6.8 | 0.8% | Sep 23, 2024 | Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2024-23933 | MEDIUM | 6.8 | 0.7% | Sep 23, 2024 | Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows p... |
| CVE-2024-23922 | MEDIUM | 6.8 | 1.7% | Sep 23, 2024 | Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows p... |
| CVE-2024-46241 | MEDIUM | 5.9 | 0.2% | Sep 23, 2024 | PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in... |
| CVE-2024-46544 | MEDIUM | 5.9 | 0.3% | Sep 23, 2024 | Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared mem... |
| CVE-2024-8903 | MEDIUM | 4.7 | 0.1% | Sep 23, 2024 | Local active protection service settings manipulation due to unnecessary privileges assignment. The following products a... |
| CVE-2024-8758 | MEDIUM | 4.8 | 0.4% | Sep 23, 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now