2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21918 | HIGH | 7.8 | 0.2% | Mar 26, 2024 | A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user... |
| CVE-2024-21913 | HIGH | 7.8 | 0.2% | Mar 26, 2024 | A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially al... |
| CVE-2024-21912 | HIGH | 7.8 | 0.3% | Mar 26, 2024 | An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malicious user insert una... |
| CVE-2024-23722 | HIGH | 7.5 | 0.9% | Mar 26, 2024 | In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content... |
| CVE-2024-23482 | HIGH | 7.8 | 0.3% | Mar 26, 2024 | The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fi... |
| CVE-2024-2891 | HIGH | 8.8 | 1.7% | Mar 26, 2024 | A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. Affected is the function formQuic... |
| CVE-2024-30235 | HIGH | 8.8 | 0.4% | Mar 26, 2024 | Missing Authorization vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page G... |
| CVE-2024-30234 | HIGH | 8.8 | 0.5% | Mar 26, 2024 | Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1. |
| CVE-2024-1933 | HIGH | 7.1 | 0.2% | Mar 26, 2024 | Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an atta... |
| CVE-2024-30231 | HIGH | 7.2 | 0.6% | Mar 26, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This is... |
| CVE-2024-28093 | HIGH | 8.8 | 0.5% | Mar 26, 2024 | The TELNET service of AdTran NetVanta 3120 18.01.01.00.E devices is enabled by default, and has default credentials for ... |
| CVE-2024-24799 | HIGH | 8.8 | 0.5% | Mar 26, 2024 | Missing Authorization vulnerability in WooCommerce WooCommerce Box Office.This issue affects WooCommerce Box Office: fro... |
| CVE-2024-2904 | HIGH | 8.8 | 0.2% | Mar 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through ... |
| CVE-2024-28131 | HIGH | 7.8 | 0.2% | Mar 26, 2024 | EasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer,... |
| CVE-2024-28033 | HIGH | 7.3 | 1.0% | Mar 26, 2024 | OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker... |
| CVE-2024-29195 | HIGH | 8.1 | 5.0% | Mar 26, 2024 | The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used ... |
| CVE-2024-29189 | HIGH | 7.8 | 0.3% | Mar 26, 2024 | PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ans... |
| CVE-2024-0866 | HIGH | 8.1 | 0.7% | Mar 26, 2024 | The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and in... |
| CVE-2024-29302 | HIGH | 7.5 | 0.8% | Mar 26, 2024 | SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php. |
| CVE-2024-29301 | HIGH | 7.5 | 0.8% | Mar 26, 2024 | SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id= |
| CVE-2024-1973 | HIGH | 8.5 | 0.4% | Mar 25, 2024 | By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to ele... |
| CVE-2024-2427 | HIGH | 7.5 | 0.7% | Mar 25, 2024 | A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling i... |
| CVE-2024-2426 | HIGH | 7.5 | 2.8% | Mar 25, 2024 | A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in ... |
| CVE-2024-2425 | HIGH | 7.5 | 2.8% | Mar 25, 2024 | A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in ... |
| CVE-2024-29515 | HIGH | 8.8 | 1.2% | Mar 25, 2024 | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via upload... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now