2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41918 | MEDIUM | 6.1 | 0.3% | Aug 29, 2024 | 'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable t... |
| CVE-2024-8250 | MEDIUM | 5.5 | 0.3% | Aug 29, 2024 | NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or... |
| CVE-2024-45232 | MEDIUM | 5.3 | 0.3% | Aug 29, 2024 | An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the ... |
| CVE-2024-45057 | MEDIUM | 6.1 | 0.3% | Aug 28, 2024 | i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators... |
| CVE-2024-45048 | MEDIUM | 6.5 | 0.6% | Aug 28, 2024 | PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypas... |
| CVE-2024-45046 | MEDIUM | 5.4 | 0.4% | Aug 28, 2024 | PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In affected versions `\PhpOffice\PhpSpre... |
| CVE-2024-45054 | MEDIUM | 6.7 | 0.3% | Aug 28, 2024 | Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resource... |
| CVE-2024-45043 | MEDIUM | 5.3 | 0.5% | Aug 28, 2024 | The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream mess... |
| CVE-2024-43805 | MEDIUM | 6.1 | 0.4% | Aug 28, 2024 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit... |
| CVE-2024-44915 | MEDIUM | 5.5 | 0.3% | Aug 28, 2024 | An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a... |
| CVE-2024-44914 | MEDIUM | 5.5 | 0.3% | Aug 28, 2024 | An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a... |
| CVE-2024-44913 | MEDIUM | 5.5 | 0.3% | Aug 28, 2024 | An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a... |
| CVE-2024-7744 | MEDIUM | 6.5 | 0.7% | Aug 28, 2024 | In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path... |
| CVE-2024-6053 | MEDIUM | 4.3 | 0.4% | Aug 28, 2024 | Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamV... |
| CVE-2024-41565 | MEDIUM | 5.3 | 0.3% | Aug 28, 2024 | JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in In... |
| CVE-2024-41564 | MEDIUM | 5.3 | 0.3% | Aug 28, 2024 | EMI v.1.1.10 and before, fixed in v.1.1.11, contains an Improper Validation of Specified Index, Position, or Offset in I... |
| CVE-2024-20413 | MEDIUM | 6.7 | 0.1% | Aug 28, 2024 | A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash ... |
| CVE-2024-20411 | MEDIUM | 6.7 | 0.2% | Aug 28, 2024 | A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash ... |
| CVE-2024-20289 | MEDIUM | 4.4 | 0.2% | Aug 28, 2024 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execu... |
| CVE-2024-20279 | MEDIUM | 4.3 | 0.3% | Aug 28, 2024 | A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (... |
| CVE-2024-42900 | MEDIUM | 6.1 | 0.3% | Aug 28, 2024 | Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of th... |
| CVE-2024-42698 | MEDIUM | 5.3 | 0.3% | Aug 28, 2024 | Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset... |
| CVE-2024-8195 | MEDIUM | 5.3 | 0.5% | Aug 28, 2024 | The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability... |
| CVE-2024-7447 | MEDIUM | 5.3 | 0.4% | Aug 28, 2024 | The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress... |
| CVE-2024-6450 | MEDIUM | 6.1 | 0.3% | Aug 28, 2024 | HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unaut... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now