2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37068 | HIGH | 7.5 | 0.2% | Sep 7, 2024 | IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms t... |
| CVE-2024-7620 | MEDIUM | 6.6 | 0.7% | Sep 7, 2024 | The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2024-7112 | MEDIUM | 6.5 | 0.5% | Sep 7, 2024 | The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘s... |
| CVE-2024-6010 | MEDIUM | 5.3 | 0.4% | Sep 7, 2024 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to price manipulation in all versions up to, and incl... |
| CVE-2024-1596 | MEDIUM | 6.1 | 0.4% | Sep 7, 2024 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e... |
| CVE-2024-8538 | MEDIUM | 4.3 | 0.6% | Sep 7, 2024 | The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in a... |
| CVE-2024-8523 | HIGH | 7.2 | 1.0% | Sep 7, 2024 | A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatD... |
| CVE-2024-6849 | MEDIUM | 5.4 | 0.3% | Sep 7, 2024 | The Preloader Plus – WordPress Loading Screen Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-8521 | MEDIUM | 6.1 | 0.5% | Sep 7, 2024 | A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index o... |
| CVE-2024-45498 | HIGH | 8.8 | 1.2% | Sep 7, 2024 | Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an ... |
| CVE-2024-45034 | HIGH | 8.8 | 1.7% | Sep 7, 2024 | Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG fold... |
| CVE-2024-8439 | — | — | — | Sep 6, 2024 | Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdra... |
| CVE-2024-45771 | CRITICAL | 9.8 | 0.5% | Sep 6, 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin... |
| CVE-2024-44839 | CRITICAL | 9.8 | 0.5% | Sep 6, 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.... |
| CVE-2024-44838 | CRITICAL | 9.8 | 0.5% | Sep 6, 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin... |
| CVE-2024-44845 | HIGH | 8.8 | 2.0% | Sep 6, 2024 | DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value para... |
| CVE-2024-44844 | HIGH | 8.8 | 1.9% | Sep 6, 2024 | DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name param... |
| CVE-2024-34158 | HIGH | 7.5 | 1.0% | Sep 6, 2024 | Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion. |
| CVE-2024-34156 | HIGH | 7.5 | 1.1% | Sep 6, 2024 | Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. T... |
| CVE-2024-34155 | MEDIUM | 4.3 | 0.8% | Sep 6, 2024 | Calling any of the Parse functions on Go source code which contains deeply nested literals can cause a panic due to stac... |
| CVE-2024-7652 | HIGH | 7.5 | 0.7% | Sep 6, 2024 | An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially... |
| CVE-2024-8394 | MEDIUM | 6.5 | 0.3% | Sep 6, 2024 | When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a p... |
| CVE-2024-45295 | — | — | — | Sep 6, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-45294. Reason: This candidate is a ... |
| CVE-2024-38642 | HIGH | 7.8 | 0.1% | Sep 6, 2024 | An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability co... |
| CVE-2024-38641 | HIGH | 7.8 | 0.5% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now