2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43797 | MEDIUM | 4.3 | 0.5% | Sep 2, 2024 | audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or ac... |
| CVE-2024-43792 | MEDIUM | 6.1 | 0.3% | Sep 2, 2024 | Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 o... |
| CVE-2024-28100 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular use... |
| CVE-2024-8004 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER... |
| CVE-2024-7939 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an ... |
| CVE-2024-7938 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x thr... |
| CVE-2024-7932 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allow... |
| CVE-2024-38858 | MEDIUM | 6.1 | 0.3% | Sep 2, 2024 | Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts... |
| CVE-2024-33043 | MEDIUM | 5.5 | 0.1% | Sep 2, 2024 | Transient DOS while handling PS event when Program Service name length offset value is set to 255. |
| CVE-2024-33016 | MEDIUM | 6.8 | 0.2% | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. |
| CVE-2024-7692 | MEDIUM | 6.1 | 0.3% | Sep 2, 2024 | The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2024-7691 | MEDIUM | 6.1 | 0.4% | Sep 2, 2024 | The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthe... |
| CVE-2024-7690 | MEDIUM | 4.3 | 0.2% | Sep 2, 2024 | The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could al... |
| CVE-2024-7354 | MEDIUM | 6.1 | 0.7% | Sep 2, 2024 | The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leadin... |
| CVE-2024-8365 | MEDIUM | 6.5 | 0.5% | Sep 2, 2024 | Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers ... |
| CVE-2024-45528 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS. |
| CVE-2024-45527 | MEDIUM | 6.1 | 0.2% | Sep 2, 2024 | REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSR... |
| CVE-2024-39612 | MEDIUM | 5.5 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
| CVE-2024-38382 | MEDIUM | 5.5 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
| CVE-2024-28044 | MEDIUM | 5.5 | 0.1% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow. |
| CVE-2024-20088 | MEDIUM | 4.4 | 0.1% | Sep 2, 2024 | In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio... |
| CVE-2024-20087 | MEDIUM | 6.7 | 0.1% | Sep 2, 2024 | In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p... |
| CVE-2024-20086 | MEDIUM | 6.7 | 0.1% | Sep 2, 2024 | In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p... |
| CVE-2024-20085 | MEDIUM | 4.4 | 0.1% | Sep 2, 2024 | In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information dis... |
| CVE-2024-20084 | MEDIUM | 4.4 | 0.1% | Sep 2, 2024 | In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information dis... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now