2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0258 | HIGH | 8.6 | 0.3% | Mar 8, 2024 | The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.... |
| CVE-2024-25729 | HIGH | 8.8 | 0.5% | Mar 8, 2024 | Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access. (T... |
| CVE-2024-2267 | HIGH | 7.5 | 0.5% | Mar 7, 2024 | A vulnerability was found in keerti1924 Online-Book-Store-Website 1.0 and classified as problematic. This issue affects ... |
| CVE-2024-2265 | HIGH | 7.5 | 0.8% | Mar 7, 2024 | A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affe... |
| CVE-2024-28115 | HIGH | 7.8 | 0.2% | Mar 7, 2024 | FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficient... |
| CVE-2024-1986 | HIGH | 8.8 | 1.3% | Mar 7, 2024 | The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type ... |
| CVE-2024-0203 | HIGH | 8.8 | 0.3% | Mar 7, 2024 | The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. Thi... |
| CVE-2024-1773 | HIGH | 8.8 | 1.0% | Mar 7, 2024 | The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all ver... |
| CVE-2024-22752 | HIGH | 8.1 | 0.6% | Mar 7, 2024 | Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use o... |
| CVE-2024-1442 | HIGH | 8.8 | 0.8% | Mar 7, 2024 | A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doin... |
| CVE-2024-27733 | HIGH | 7.7 | 0.3% | Mar 7, 2024 | File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitr... |
| CVE-2024-1170 | HIGH | 8.2 | 0.7% | Mar 7, 2024 | The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p... |
| CVE-2024-1169 | HIGH | 7.5 | 0.6% | Mar 7, 2024 | The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p... |
| CVE-2024-1931 | HIGH | 7.5 | 2.5% | Mar 7, 2024 | NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of se... |
| CVE-2024-1382 | HIGH | 8.8 | 0.9% | Mar 7, 2024 | The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ... |
| CVE-2024-28215 | HIGH | 7.5 | 0.5% | Mar 7, 2024 | nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which ... |
| CVE-2024-28094 | HIGH | 8.8 | 0.6% | Mar 7, 2024 | Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the au... |
| CVE-2024-0815 | HIGH | 8.8 | 1.1% | Mar 7, 2024 | Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0 |
| CVE-2024-0817 | HIGH | 7.8 | 1.2% | Mar 7, 2024 | Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0 |
| CVE-2024-26566 | HIGH | 8.2 | 0.6% | Mar 7, 2024 | An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification co... |
| CVE-2024-24375 | HIGH | 7.5 | 0.5% | Mar 7, 2024 | SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/adm... |
| CVE-2024-1299 | HIGH | 8.1 | 0.5% | Mar 7, 2024 | A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to ... |
| CVE-2024-0199 | HIGH | 8 | 0.7% | Mar 7, 2024 | An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to ... |
| CVE-2024-28110 | HIGH | 7.5 | 0.7% | Mar 6, 2024 | Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15... |
| CVE-2024-27917 | HIGH | 7.5 | 0.6% | Mar 6, 2024 | Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session C... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now