2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38640 | MEDIUM | 5.4 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability... |
| CVE-2024-32771 | LOW | 2.4 | 0.2% | Sep 6, 2024 | An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP oper... |
| CVE-2024-32763 | HIGH | 8.8 | 0.6% | Sep 6, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-32762 | MEDIUM | 6.1 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability cou... |
| CVE-2024-27126 | MEDIUM | 5.4 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability ... |
| CVE-2024-27125 | MEDIUM | 4.8 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could a... |
| CVE-2024-27122 | MEDIUM | 5.4 | 0.2% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability ... |
| CVE-2024-21906 | MEDIUM | 4.7 | 0.8% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2024-21904 | MEDIUM | 6.5 | 0.3% | Sep 6, 2024 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul... |
| CVE-2024-21903 | MEDIUM | 4.7 | 0.8% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2024-21898 | HIGH | 8.8 | 1.2% | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2024-21897 | MEDIUM | 5.4 | 0.3% | Sep 6, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi... |
| CVE-2024-8517 | CRITICAL | 9.8 | 94.6% | Sep 6, 2024 | SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacke... |
| CVE-2024-8509 | HIGH | 7.5 | 0.6% | Sep 6, 2024 | A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to e... |
| CVE-2024-45758 | CRITICAL | 9.1 | 0.9% | Sep 6, 2024 | H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file r... |
| CVE-2024-45294 | HIGH | 8.6 | 1.0% | Sep 6, 2024 | The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator)... |
| CVE-2024-44408 | HIGH | 7.5 | 0.6% | Sep 6, 2024 | D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration... |
| CVE-2024-44402 | CRITICAL | 9.8 | 3.1% | Sep 6, 2024 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm. |
| CVE-2024-44401 | CRITICAL | 9.8 | 2.9% | Sep 6, 2024 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file |
| CVE-2024-25584 | MEDIUM | 5.3 | 0.2% | Sep 6, 2024 | Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This... |
| CVE-2024-8428 | HIGH | 8.8 | 0.5% | Sep 6, 2024 | The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Di... |
| CVE-2024-7622 | MEDIUM | 4.3 | 0.4% | Sep 6, 2024 | The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing cap... |
| CVE-2024-7611 | MEDIUM | 5.4 | 0.3% | Sep 6, 2024 | The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2024-7599 | MEDIUM | 5.4 | 0.3% | Sep 6, 2024 | The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ para... |
| CVE-2024-7493 | CRITICAL | 9.8 | 0.6% | Sep 6, 2024 | The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now