2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45752 | HIGH | 7.3 | 0.3% | Sep 19, 2024 | logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an u... |
| CVE-2024-7785 | CRITICAL | 9.3 | 0.4% | Sep 19, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ece Softwar... |
| CVE-2024-46394 | HIGH | 8.8 | 0.3% | Sep 19, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add |
| CVE-2024-46382 | HIGH | 7.5 | 0.6% | Sep 19, 2024 | A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via ... |
| CVE-2024-8986 | CRITICAL | 9.1 | 0.5% | Sep 19, 2024 | The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI f... |
| CVE-2024-8354 | MEDIUM | 5.5 | 0.3% | Sep 19, 2024 | A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to ... |
| CVE-2024-45770 | MEDIUM | 4.4 | 0.3% | Sep 19, 2024 | A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a ... |
| CVE-2024-45769 | MEDIUM | 5.5 | 0.3% | Sep 19, 2024 | A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to... |
| CVE-2024-47089 | MEDIUM | 6.5 | 0.2% | Sep 19, 2024 | This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API ... |
| CVE-2024-47088 | CRITICAL | 9.8 | 0.5% | Sep 19, 2024 | This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attemp... |
| CVE-2024-47087 | MEDIUM | 6.5 | 0.4% | Sep 19, 2024 | This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID ... |
| CVE-2024-47086 | MEDIUM | 6.5 | 0.5% | Sep 19, 2024 | This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism ... |
| CVE-2024-47085 | MEDIUM | 6.5 | 0.4% | Sep 19, 2024 | This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClic... |
| CVE-2024-46946 | CRITICAL | 9.8 | 1.3% | Sep 19, 2024 | langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbit... |
| CVE-2024-8850 | MEDIUM | 6.1 | 0.4% | Sep 19, 2024 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' ... |
| CVE-2024-8364 | MEDIUM | 5.4 | 0.3% | Sep 19, 2024 | The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-pre... |
| CVE-2024-7254 | HIGH | 7.5 | 2.8% | Sep 19, 2024 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGRO... |
| CVE-2024-47059 | MEDIUM | 4.3 | 0.3% | Sep 18, 2024 | When logging in with the correct username and incorrect weak password, the user receives the notification, that their pa... |
| CVE-2024-37406 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, w... |
| CVE-2024-47058 | MEDIUM | 4.8 | 0.2% | Sep 18, 2024 | With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be use... |
| CVE-2024-47050 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variabl... |
| CVE-2024-46377 | CRITICAL | 9.8 | 1.2% | Sep 18, 2024 | Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function ... |
| CVE-2024-46376 | CRITICAL | 9.8 | 1.1% | Sep 18, 2024 | Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function... |
| CVE-2024-46375 | CRITICAL | 9.8 | 1.1% | Sep 18, 2024 | Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the ... |
| CVE-2024-46374 | CRITICAL | 9.8 | 0.5% | Sep 18, 2024 | Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now