2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8797 | MEDIUM | 6.1 | 0.5% | Sep 14, 2024 | The WP Booking System – Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the... |
| CVE-2024-8724 | MEDIUM | 6.1 | 0.4% | Sep 14, 2024 | The Waitlist Woocommerce ( Back in stock notifier ) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting... |
| CVE-2024-8775 | MEDIUM | 5.5 | 0.3% | Sep 14, 2024 | A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext durin... |
| CVE-2024-6259 | MEDIUM | 6.5 | 0.6% | Sep 13, 2024 | BT: HCI: adv_ext_report Improper discarding in adv_ext_report |
| CVE-2024-44096 | MEDIUM | 4.4 | 0.1% | Sep 13, 2024 | there is a possible arbitrary read due to an insecure default value. This could lead to local information disclosure wit... |
| CVE-2024-6137 | MEDIUM | 6.5 | 0.5% | Sep 13, 2024 | BT: Classic: SDP OOB access in get_att_search_list |
| CVE-2024-6135 | MEDIUM | 6.5 | 0.4% | Sep 13, 2024 | BT:Classic: Multiple missing buf length checks |
| CVE-2024-5931 | MEDIUM | 6.5 | 0.4% | Sep 13, 2024 | BT: Unchecked user input in bap_broadcast_assistant |
| CVE-2024-8783 | MEDIUM | 5.4 | 0.4% | Sep 13, 2024 | A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown funct... |
| CVE-2024-6258 | MEDIUM | 6.5 | 0.4% | Sep 13, 2024 | BT: Missing length checks of net_buf in rfcomm_handle_data |
| CVE-2024-5754 | MEDIUM | 6.5 | 0.3% | Sep 13, 2024 | BT: Encryption procedure host vulnerability |
| CVE-2024-8059 | MEDIUM | 4.3 | 0.2% | Sep 13, 2024 | IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters. |
| CVE-2024-7756 | MEDIUM | 6.8 | 0.3% | Sep 13, 2024 | A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to e... |
| CVE-2024-4550 | MEDIUM | 6.7 | 0.2% | Sep 13, 2024 | A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could a... |
| CVE-2024-45105 | MEDIUM | 6.7 | 0.2% | Sep 13, 2024 | An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSys... |
| CVE-2024-45104 | MEDIUM | 6.5 | 0.2% | Sep 13, 2024 | A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXC... |
| CVE-2024-45103 | MEDIUM | 4.3 | 0.3% | Sep 13, 2024 | A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface withou... |
| CVE-2024-45101 | MEDIUM | 6.8 | 0.2% | Sep 13, 2024 | A privilege escalation vulnerability was discovered when Single Sign On (SSO) is enabled that could allow an attacker to... |
| CVE-2024-3100 | MEDIUM | 6.7 | 0.2% | Sep 13, 2024 | A potential buffer overflow vulnerability was reported in some Lenovo Notebook products that could allow a local attacke... |
| CVE-2024-39926 | MEDIUM | 5.4 | 0.4% | Sep 13, 2024 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to th... |
| CVE-2024-39925 | MEDIUM | 6.5 | 0.6% | Sep 13, 2024 | An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who l... |
| CVE-2024-6867 | MEDIUM | 6.5 | 0.4% | Sep 13, 2024 | An information disclosure vulnerability exists in the lunary-ai/lunary, specifically in the `runs/{run_id}/related` endp... |
| CVE-2024-6582 | MEDIUM | 4.3 | 0.4% | Sep 13, 2024 | A broken access control vulnerability exists in the latest version of lunary-ai/lunary. The `saml.ts` file allows a user... |
| CVE-2024-6087 | MEDIUM | 6.5 | 0.4% | Sep 13, 2024 | An improper access control vulnerability exists in lunary-ai/lunary at the latest commit (a761d83) on the main branch. T... |
| CVE-2024-31416 | MEDIUM | 6.5 | 0.3% | Sep 13, 2024 | The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the too... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now