2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39434 | MEDIUM | 4.4 | 0.1% | Sep 27, 2024 | In drm service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of... |
| CVE-2024-39433 | MEDIUM | 4.4 | 0.1% | Sep 27, 2024 | In drm service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial o... |
| CVE-2024-39432 | MEDIUM | 4.5 | 0.2% | Sep 27, 2024 | In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote deni... |
| CVE-2024-39431 | MEDIUM | 4.5 | 0.2% | Sep 27, 2024 | In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote den... |
| CVE-2024-9049 | MEDIUM | 5.4 | 0.3% | Sep 27, 2024 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-9029 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read... |
| CVE-2024-8991 | MEDIUM | 5.4 | 0.4% | Sep 27, 2024 | The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and o... |
| CVE-2024-8681 | MEDIUM | 5.4 | 0.4% | Sep 27, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Medi... |
| CVE-2024-7400 | HIGH | 8.5 | 0.2% | Sep 27, 2024 | The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file... |
| CVE-2024-9130 | HIGH | 7.2 | 0.7% | Sep 27, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via... |
| CVE-2024-8965 | MEDIUM | 5.4 | 0.3% | Sep 27, 2024 | The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom ... |
| CVE-2024-8922 | HIGH | 8.8 | 0.8% | Sep 27, 2024 | The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Inject... |
| CVE-2024-7714 | HIGH | 7.5 | 0.8% | Sep 27, 2024 | The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls ... |
| CVE-2024-7713 | HIGH | 7.5 | 0.3% | Sep 27, 2024 | The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, al... |
| CVE-2024-7011 | MEDIUM | 6.5 | 0.3% | Sep 27, 2024 | Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, ... |
| CVE-2024-8974 | MEDIUM | 4.3 | 0.3% | Sep 26, 2024 | Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 ... |
| CVE-2024-4099 | MEDIUM | 5.3 | 0.3% | Sep 26, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to ... |
| CVE-2024-47177 | — | — | — | Sep 26, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-47076, CVE-2024-47175, CVE-2024-471... |
| CVE-2024-47176 | MEDIUM | 5.3 | 62.3% | Sep 26, 2024 | CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality inclu... |
| CVE-2024-47175 | CRITICAL | 9.8 | 73.1% | Sep 26, 2024 | CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libpp... |
| CVE-2024-47076 | HIGH | 8.6 | 83.4% | Sep 26, 2024 | CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the for... |
| CVE-2024-40508 | HIGH | 7.3 | 0.7% | Sep 26, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-40507 | HIGH | 7.3 | 0.7% | Sep 26, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-40506 | HIGH | 7.3 | 0.7% | Sep 26, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-6769 | HIGH | 8.4 | 1.1% | Sep 26, 2024 | A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Win... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now