2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4782 | MEDIUM | 6.5 | 0.3% | Aug 16, 2024 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a... |
| CVE-2024-4781 | MEDIUM | 6.5 | 0.3% | Aug 16, 2024 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a... |
| CVE-2024-43810 | MEDIUM | 5.4 | 0.3% | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin |
| CVE-2024-43809 | MEDIUM | 6.1 | 0.3% | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page |
| CVE-2024-43808 | MEDIUM | 5.4 | 0.2% | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin |
| CVE-2024-43807 | MEDIUM | 5.4 | 0.3% | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page |
| CVE-2024-43381 | MEDIUM | 5.4 | 0.4% | Aug 16, 2024 | reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Store... |
| CVE-2024-7144 | MEDIUM | 5.4 | 0.3% | Aug 16, 2024 | The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters... |
| CVE-2024-42464 | MEDIUM | 6.5 | 0.3% | Aug 16, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Uti... |
| CVE-2024-42463 | MEDIUM | 6.5 | 0.4% | Aug 16, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Uti... |
| CVE-2024-7147 | MEDIUM | 6.4 | 0.3% | Aug 16, 2024 | The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple placeholder p... |
| CVE-2024-7136 | MEDIUM | 6.4 | 0.3% | Aug 16, 2024 | The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions u... |
| CVE-2024-25008 | MEDIUM | 6.8 | 0.3% | Aug 16, 2024 | Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Valida... |
| CVE-2024-7501 | MEDIUM | 4.2 | 0.2% | Aug 16, 2024 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2024-7301 | MEDIUM | 6.1 | 0.4% | Aug 16, 2024 | The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ... |
| CVE-2024-7422 | MEDIUM | 4.3 | 0.2% | Aug 16, 2024 | The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2024-7852 | MEDIUM | 5.4 | 0.4% | Aug 16, 2024 | A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as problematic. This issue... |
| CVE-2024-43374 | MEDIUM | 4.7 | 0.3% | Aug 16, 2024 | The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new fi... |
| CVE-2024-7844 | MEDIUM | 5.4 | 0.5% | Aug 15, 2024 | A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affect... |
| CVE-2024-34742 | MEDIUM | 5.5 | 0.1% | Aug 15, 2024 | In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to ... |
| CVE-2024-42488 | MEDIUM | 6.8 | 0.5% | Aug 15, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.14.14 and... |
| CVE-2024-42487 | MEDIUM | 4.3 | 0.5% | Aug 15, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In the 1.15 branch prior to 1... |
| CVE-2024-7867 | MEDIUM | 6.2 | 0.2% | Aug 15, 2024 | In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero. |
| CVE-2024-7866 | MEDIUM | 5.5 | 0.2% | Aug 15, 2024 | In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow. |
| CVE-2024-42476 | MEDIUM | 6.5 | 0.2% | Aug 15, 2024 | In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `st... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now