2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45012 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: nouveau/firmware: use dma non-coherent allocator C... |
| CVE-2024-45011 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Check USB endpoints when probing de... |
| CVE-2024-45010 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only mark 'subflow' endp as available A... |
| CVE-2024-45009 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: only decrement add_addr_accepted for MPJ... |
| CVE-2024-44851 | MEDIUM | 5.4 | 0.4% | Sep 11, 2024 | A stored cross-site scripting (XSS) vulnerability in the Discussion section of Perfex CRM v1.1.0 allows attackers to exe... |
| CVE-2024-41868 | MEDIUM | 5.5 | 0.2% | Sep 11, 2024 | Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disc... |
| CVE-2024-4465 | MEDIUM | 5 | 0.2% | Sep 11, 2024 | An access control vulnerability was discovered in the Reports section due to a specific access restriction not being pro... |
| CVE-2024-43793 | MEDIUM | 6.4 | 0.3% | Sep 11, 2024 | Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 o... |
| CVE-2024-8646 | MEDIUM | 6.1 | 0.4% | Sep 11, 2024 | In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerab... |
| CVE-2024-5416 | MEDIUM | 5.4 | 0.4% | Sep 11, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-45789 | MEDIUM | 4.3 | 0.2% | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API... |
| CVE-2024-45787 | MEDIUM | 6.5 | 0.4% | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in... |
| CVE-2024-45786 | MEDIUM | 6.5 | 0.4% | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints.... |
| CVE-2024-8096 | MEDIUM | 6.5 | 0.7% | Sep 11, 2024 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify tha... |
| CVE-2024-8045 | MEDIUM | 5.4 | 0.3% | Sep 11, 2024 | The Advanced WordPress Backgrounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘imageTag’ ... |
| CVE-2024-8440 | MEDIUM | 5.4 | 0.4% | Sep 11, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-7716 | MEDIUM | 4.8 | 0.3% | Sep 11, 2024 | The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-3899 | MEDIUM | 4.8 | 0.3% | Sep 11, 2024 | The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings... |
| CVE-2024-7727 | MEDIUM | 5.3 | 0.4% | Sep 11, 2024 | The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of ... |
| CVE-2024-7721 | MEDIUM | 4.3 | 0.3% | Sep 11, 2024 | The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modificati... |
| CVE-2024-39808 | MEDIUM | 4.6 | 0.2% | Sep 11, 2024 | Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows ... |
| CVE-2024-24972 | MEDIUM | 6.5 | 0.3% | Sep 11, 2024 | Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface... |
| CVE-2024-23906 | MEDIUM | 6.1 | 0.3% | Sep 11, 2024 | Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnost... |
| CVE-2024-40659 | MEDIUM | 5.5 | 0.1% | Sep 11, 2024 | In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore... |
| CVE-2024-40656 | MEDIUM | 5.5 | 0.1% | Sep 11, 2024 | In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across user... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now