2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9451 | MEDIUM | 6.4 | 0.4% | Oct 9, 2024 | The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' para... |
| CVE-2024-9449 | MEDIUM | 6.4 | 0.3% | Oct 9, 2024 | The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all version... |
| CVE-2024-39586 | MEDIUM | 4.3 | 0.2% | Oct 9, 2024 | Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high ... |
| CVE-2024-39440 | MEDIUM | 4.4 | 0.1% | Oct 9, 2024 | In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of ser... |
| CVE-2024-39439 | MEDIUM | 4.4 | 0.1% | Oct 9, 2024 | In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o... |
| CVE-2024-39438 | MEDIUM | 6.7 | 0.3% | Oct 9, 2024 | In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l... |
| CVE-2024-39437 | MEDIUM | 6.7 | 0.3% | Oct 9, 2024 | In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l... |
| CVE-2024-39436 | MEDIUM | 6.7 | 0.3% | Oct 9, 2024 | In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to l... |
| CVE-2024-5968 | MEDIUM | 4.8 | 0.3% | Oct 9, 2024 | The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery set... |
| CVE-2024-47191 | HIGH | 7.1 | 0.3% | Oct 9, 2024 | pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context ... |
| CVE-2024-45160 | CRITICAL | 9.1 | 0.5% | Oct 9, 2024 | Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 clien... |
| CVE-2024-42934 | MEDIUM | 5 | 0.4% | Oct 9, 2024 | OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting ... |
| CVE-2024-32608 | CRITICAL | 9.8 | 0.7% | Oct 9, 2024 | HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer a... |
| CVE-2024-45179 | HIGH | 7.2 | 2.6% | Oct 9, 2024 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validatio... |
| CVE-2024-35288 | HIGH | 7.8 | 0.3% | Oct 9, 2024 | Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because... |
| CVE-2024-25286 | — | — | — | Oct 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and... |
| CVE-2024-25285 | — | — | — | Oct 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and... |
| CVE-2024-25284 | — | — | — | Oct 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and... |
| CVE-2024-25283 | — | — | — | Oct 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and... |
| CVE-2024-25282 | — | — | — | Oct 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and... |
| CVE-2024-7963 | MEDIUM | 6.4 | 0.3% | Oct 9, 2024 | The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multi... |
| CVE-2024-9603 | HIGH | 8.8 | 0.5% | Oct 8, 2024 | Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2024-9602 | HIGH | 8.8 | 0.8% | Oct 8, 2024 | Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memo... |
| CVE-2024-9412 | HIGH | 8.4 | 0.4% | Oct 8, 2024 | An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthor... |
| CVE-2024-36814 | MEDIUM | 4.9 | 0.8% | Oct 8, 2024 | An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now