2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46935 | HIGH | 7.5 | 0.6% | Sep 25, 2024 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers... |
| CVE-2024-46934 | MEDIUM | 6.1 | 0.3% | Sep 25, 2024 | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XS... |
| CVE-2024-46612 | CRITICAL | 9.8 | 0.6% | Sep 25, 2024 | IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication... |
| CVE-2024-46610 | HIGH | 7.5 | 0.4% | Sep 25, 2024 | An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including... |
| CVE-2024-46609 | HIGH | 7.5 | 0.7% | Sep 25, 2024 | An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticat... |
| CVE-2024-46607 | HIGH | 7.6 | 0.6% | Sep 25, 2024 | Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values a... |
| CVE-2024-45599 | LOW | 3.8 | 0.2% | Sep 25, 2024 | Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access ... |
| CVE-2024-45373 | HIGH | 8.8 | 0.5% | Sep 25, 2024 | Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator. |
| CVE-2024-45066 | CRITICAL | 9.8 | 0.8% | Sep 25, 2024 | A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject a... |
| CVE-2024-43693 | CRITICAL | 9.8 | 0.8% | Sep 25, 2024 | A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inj... |
| CVE-2024-43692 | CRITICAL | 9.8 | 0.5% | Sep 25, 2024 | An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting t... |
| CVE-2024-43423 | CRITICAL | 9.8 | 0.7% | Sep 25, 2024 | The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that... |
| CVE-2024-42797 | CRITICAL | 9.8 | 0.5% | Sep 25, 2024 | An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Managem... |
| CVE-2024-42507 | CRITICAL | 9.8 | 1.4% | Sep 25, 2024 | Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s... |
| CVE-2024-42506 | CRITICAL | 9.8 | 1.4% | Sep 25, 2024 | Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s... |
| CVE-2024-42505 | CRITICAL | 9.8 | 1.5% | Sep 25, 2024 | Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s... |
| CVE-2024-41725 | MEDIUM | 6.1 | 0.4% | Sep 25, 2024 | ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may ... |
| CVE-2024-39928 | HIGH | 7.5 | 0.5% | Sep 25, 2024 | In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the To... |
| CVE-2024-38324 | MEDIUM | 6.5 | 0.3% | Sep 25, 2024 | IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registrati... |
| CVE-2024-21545 | HIGH | 8.2 | 0.4% | Sep 25, 2024 | Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient saf... |
| CVE-2024-8794 | MEDIUM | 5.3 | 0.4% | Sep 24, 2024 | The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and includi... |
| CVE-2024-8791 | CRITICAL | 9.8 | 0.7% | Sep 24, 2024 | The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnera... |
| CVE-2024-8671 | CRITICAL | 9.1 | 1.0% | Sep 24, 2024 | The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insuffi... |
| CVE-2024-8628 | MEDIUM | 5.4 | 0.3% | Sep 24, 2024 | The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable ... |
| CVE-2024-8624 | CRITICAL | 9.9 | 0.5% | Sep 24, 2024 | The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attrib... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now