2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6846 | MEDIUM | 5.3 | 1.3% | Sep 5, 2024 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an una... |
| CVE-2024-8178 | HIGH | 8.8 | 0.6% | Sep 5, 2024 | The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it... |
| CVE-2024-45063 | HIGH | 8.8 | 0.5% | Sep 5, 2024 | The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished p... |
| CVE-2024-43110 | HIGH | 8.8 | 0.4% | Sep 5, 2024 | The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software runni... |
| CVE-2024-43102 | CRITICAL | 10 | 0.7% | Sep 5, 2024 | Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM... |
| CVE-2024-42416 | HIGH | 8.8 | 0.4% | Sep 5, 2024 | The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbit... |
| CVE-2024-32668 | HIGH | 8.2 | 0.2% | Sep 5, 2024 | An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controll... |
| CVE-2024-45288 | HIGH | 8.4 | 0.3% | Sep 5, 2024 | A missing null-termination character in the last element of an nvlist array string can lead to writing outside the alloc... |
| CVE-2024-45287 | HIGH | 7.5 | 0.5% | Sep 5, 2024 | A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a s... |
| CVE-2024-41928 | HIGH | 8.4 | 0.2% | Sep 5, 2024 | Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bh... |
| CVE-2024-7627 | HIGH | 8.1 | 2.8% | Sep 5, 2024 | The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'check... |
| CVE-2024-45692 | HIGH | 7.5 | 0.6% | Sep 4, 2024 | Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000. |
| CVE-2024-45429 | MEDIUM | 6.1 | 0.4% | Sep 4, 2024 | Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Field... |
| CVE-2024-2166 | MEDIUM | 6.1 | 0.3% | Sep 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email S... |
| CVE-2024-20506 | MEDIUM | 6.1 | 0.3% | Sep 4, 2024 | A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2... |
| CVE-2024-20505 | HIGH | 7.5 | 0.6% | Sep 4, 2024 | A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x... |
| CVE-2024-45395 | HIGH | 7.5 | 0.4% | Sep 4, 2024 | sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in version... |
| CVE-2024-45399 | MEDIUM | 6.1 | 0.4% | Sep 4, 2024 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indi... |
| CVE-2024-45172 | MEDIUM | 6.8 | 0.4% | Sep 4, 2024 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanism... |
| CVE-2024-45008 | MEDIUM | 5.5 | 0.2% | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: Input: MT - limit max slots syzbot is reporting to... |
| CVE-2024-45007 | MEDIUM | 5.5 | 0.2% | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Don't destroy workqueue from work i... |
| CVE-2024-45006 | MEDIUM | 5.5 | 0.3% | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: xhci: Fix Panther point NULL pointer deref at full-... |
| CVE-2024-45005 | MEDIUM | 5.5 | 0.2% | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: fix validity interception issue when gis... |
| CVE-2024-45004 | MEDIUM | 5.5 | 0.1% | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: dcp: fix leak of blob encryption key... |
| CVE-2024-45003 | MEDIUM | 4.7 | 0.2% | Sep 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: vfs: Don't evict inode under the inode lru traversi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now