2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33582 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code wi... |
| CVE-2024-33581 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | A DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker t... |
| CVE-2024-33580 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | A DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with ... |
| CVE-2024-33579 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevate... |
| CVE-2024-33578 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated ... |
| CVE-2024-9869 | — | — | — | Oct 11, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-8755 | CRITICAL | 9.8 | 1.1% | Oct 11, 2024 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This ... |
| CVE-2024-47875 | MEDIUM | 6.1 | 1.1% | Oct 11, 2024 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to n... |
| CVE-2024-47830 | MEDIUM | 5.8 | 0.6% | Oct 11, 2024 | Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostn... |
| CVE-2024-47074 | CRITICAL | 9.8 | 0.6% | Oct 11, 2024 | DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source ... |
| CVE-2024-45403 | HIGH | 7.5 | 0.6% | Oct 11, 2024 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3... |
| CVE-2024-45402 | CRITICAL | 9.8 | 0.5% | Oct 11, 2024 | Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsi... |
| CVE-2024-45397 | HIGH | 7.5 | 0.4% | Oct 11, 2024 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top... |
| CVE-2024-45396 | HIGH | 7.5 | 0.6% | Oct 11, 2024 | Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attac... |
| CVE-2024-25622 | MEDIUM | 4.3 | 0.4% | Oct 11, 2024 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers... |
| CVE-2024-9002 | HIGH | 7.8 | 0.2% | Oct 11, 2024 | CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentialit... |
| CVE-2024-8531 | HIGH | 7.2 | 0.4% | Oct 11, 2024 | CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Exp... |
| CVE-2024-8530 | MEDIUM | 5.9 | 0.5% | Oct 11, 2024 | CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data whe... |
| CVE-2024-6657 | MEDIUM | 6.5 | 0.2% | Oct 11, 2024 | A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuo... |
| CVE-2024-9856 | MEDIUM | 4.8 | 0.4% | Oct 11, 2024 | A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this ... |
| CVE-2024-9855 | HIGH | 7.2 | 0.6% | Oct 11, 2024 | A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this ... |
| CVE-2024-9707 | CRITICAL | 9.8 | 9.1% | Oct 11, 2024 | The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca... |
| CVE-2024-9616 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the... |
| CVE-2024-9611 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site ... |
| CVE-2024-9610 | MEDIUM | 6.1 | 0.3% | Oct 11, 2024 | The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now