2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6449 | MEDIUM | 6.5 | 0.4% | Aug 28, 2024 | HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote co... |
| CVE-2024-7269 | MEDIUM | 5.4 | 0.4% | Aug 28, 2024 | Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ... |
| CVE-2024-44943 | MEDIUM | 5.5 | 0.2% | Aug 28, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: gup: stop abusing try_grab_folio A kernel warn... |
| CVE-2024-6312 | MEDIUM | 6.5 | 1.1% | Aug 28, 2024 | The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including,... |
| CVE-2024-4554 | MEDIUM | 5.4 | 0.3% | Aug 28, 2024 | Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. Thi... |
| CVE-2024-39771 | MEDIUM | 6.8 | 0.1% | Aug 28, 2024 | QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may a... |
| CVE-2024-6448 | MEDIUM | 5.3 | 0.5% | Aug 28, 2024 | The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to information exposure in all versions up to, an... |
| CVE-2024-7573 | MEDIUM | 5.3 | 0.4% | Aug 28, 2024 | The Relevanssi Live Ajax Search plugin for WordPress is vulnerable to argument injection in all versions up to, and incl... |
| CVE-2024-8216 | MEDIUM | 5.4 | 0.4% | Aug 27, 2024 | A vulnerability, which was classified as critical, has been found in nafisulbari/itsourcecode Insurance Management Syste... |
| CVE-2024-5814 | MEDIUM | 5.3 | 0.5% | Aug 27, 2024 | A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree... |
| CVE-2024-5288 | MEDIUM | 5.9 | 0.4% | Aug 27, 2024 | An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA k... |
| CVE-2024-45037 | MEDIUM | 6.4 | 0.3% | Aug 27, 2024 | The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers ... |
| CVE-2024-1544 | MEDIUM | 4.9 | 0.3% | Aug 27, 2024 | Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod ... |
| CVE-2024-8209 | MEDIUM | 6.1 | 0.3% | Aug 27, 2024 | A vulnerability was found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic. Aff... |
| CVE-2024-8208 | MEDIUM | 6.1 | 0.3% | Aug 27, 2024 | A vulnerability has been found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic... |
| CVE-2024-43788 | MEDIUM | 6.1 | 0.9% | Aug 27, 2024 | Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capab... |
| CVE-2024-8200 | MEDIUM | 4.3 | 0.2% | Aug 27, 2024 | The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for Wor... |
| CVE-2024-8199 | MEDIUM | 4.3 | 0.4% | Aug 27, 2024 | The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for Wor... |
| CVE-2024-40395 | MEDIUM | 6.5 | 0.6% | Aug 27, 2024 | An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, inclu... |
| CVE-2024-7941 | MEDIUM | 4.3 | 0.3% | Aug 27, 2024 | An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified U... |
| CVE-2024-8207 | MEDIUM | 6.7 | 0.2% | Aug 27, 2024 | In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating S... |
| CVE-2024-7791 | MEDIUM | 5.4 | 0.3% | Aug 27, 2024 | The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2024-6789 | MEDIUM | 6.5 | 0.6% | Aug 27, 2024 | A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 2... |
| CVE-2024-8046 | MEDIUM | 6.4 | 0.3% | Aug 27, 2024 | The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-7608 | MEDIUM | 5.9 | 0.3% | Aug 27, 2024 | An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now