2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45790 | CRITICAL | 9.8 | 0.6% | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authenticati... |
| CVE-2024-7609 | HIGH | 7.5 | 0.5% | Sep 11, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTE... |
| CVE-2024-5416 | MEDIUM | 5.4 | 0.4% | Sep 11, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-45789 | MEDIUM | 4.3 | 0.2% | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper validation of the ‘mode’ parameter in the API... |
| CVE-2024-45788 | HIGH | 7.5 | 0.5% | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API e... |
| CVE-2024-45787 | MEDIUM | 6.5 | 0.4% | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in... |
| CVE-2024-45786 | MEDIUM | 6.5 | 0.4% | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to improper access controls on its certain API endpoints.... |
| CVE-2024-8096 | MEDIUM | 6.5 | 0.7% | Sep 11, 2024 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify tha... |
| CVE-2024-45327 | HIGH | 7.5 | 0.3% | Sep 11, 2024 | An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 t... |
| CVE-2024-8277 | CRITICAL | 9.8 | 1.6% | Sep 11, 2024 | The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to,... |
| CVE-2024-8045 | MEDIUM | 5.4 | 0.3% | Sep 11, 2024 | The Advanced WordPress Backgrounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘imageTag’ ... |
| CVE-2024-7626 | HIGH | 8.1 | 0.8% | Sep 11, 2024 | The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to ar... |
| CVE-2024-8440 | MEDIUM | 5.4 | 0.4% | Sep 11, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-7716 | MEDIUM | 4.8 | 0.3% | Sep 11, 2024 | The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-3899 | MEDIUM | 4.8 | 0.3% | Sep 11, 2024 | The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings... |
| CVE-2024-7727 | MEDIUM | 5.3 | 0.4% | Sep 11, 2024 | The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of ... |
| CVE-2024-7721 | MEDIUM | 4.3 | 0.3% | Sep 11, 2024 | The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modificati... |
| CVE-2024-43690 | HIGH | 8 | 0.6% | Sep 11, 2024 | Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allo... |
| CVE-2024-21529 | HIGH | 8.8 | 0.6% | Sep 11, 2024 | Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user ... |
| CVE-2024-1656 | LOW | 2.6 | 0.2% | Sep 11, 2024 | Affected versions of Octopus Server had a weak content security policy. |
| CVE-2024-8253 | HIGH | 8.8 | 9.6% | Sep 11, 2024 | The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to ... |
| CVE-2024-39808 | MEDIUM | 4.6 | 0.2% | Sep 11, 2024 | Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows ... |
| CVE-2024-24972 | MEDIUM | 6.5 | 0.3% | Sep 11, 2024 | Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface... |
| CVE-2024-23906 | MEDIUM | 6.1 | 0.3% | Sep 11, 2024 | Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnost... |
| CVE-2024-40662 | HIGH | 7.8 | 0.1% | Sep 11, 2024 | In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This co... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now