2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33016 | MEDIUM | 6.8 | 0.2% | Sep 2, 2024 | memory corruption when an invalid firehose patch command is invoked. |
| CVE-2024-23365 | HIGH | 8.4 | 0.1% | Sep 2, 2024 | Memory corruption while releasing shared resources in MinkSocket listener thread. |
| CVE-2024-23364 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Eleme... |
| CVE-2024-23362 | HIGH | 7.1 | 0.1% | Sep 2, 2024 | Cryptographic issue while parsing RSA keys in COBR format. |
| CVE-2024-23359 | HIGH | 8.2 | 0.3% | Sep 2, 2024 | Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network. |
| CVE-2024-23358 | HIGH | 7.5 | 0.3% | Sep 2, 2024 | Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem. |
| CVE-2024-7692 | MEDIUM | 6.1 | 0.3% | Sep 2, 2024 | The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2024-7691 | MEDIUM | 6.1 | 0.4% | Sep 2, 2024 | The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthe... |
| CVE-2024-7690 | MEDIUM | 4.3 | 0.2% | Sep 2, 2024 | The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could al... |
| CVE-2024-7354 | MEDIUM | 6.1 | 0.7% | Sep 2, 2024 | The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leadin... |
| CVE-2024-8365 | MEDIUM | 6.5 | 0.5% | Sep 2, 2024 | Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers ... |
| CVE-2024-7871 | HIGH | 8.7 | 0.5% | Sep 2, 2024 | SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenti... |
| CVE-2024-45528 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS. |
| CVE-2024-45527 | MEDIUM | 6.1 | 0.2% | Sep 2, 2024 | REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSR... |
| CVE-2024-43776 | HIGH | 8.8 | 0.5% | Sep 2, 2024 | SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated us... |
| CVE-2024-43775 | HIGH | 8.8 | 0.5% | Sep 2, 2024 | SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authe... |
| CVE-2024-43774 | HIGH | 8.8 | 0.5% | Sep 2, 2024 | SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow... |
| CVE-2024-43773 | CRITICAL | 9.8 | 0.5% | Sep 2, 2024 | SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow re... |
| CVE-2024-43772 | CRITICAL | 9.8 | 0.5% | Sep 2, 2024 | SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow ... |
| CVE-2024-41160 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens... |
| CVE-2024-41157 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens... |
| CVE-2024-39816 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
| CVE-2024-39775 | HIGH | 7.5 | 0.4% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a remote attacker cause information leak through out-of-bounds Read. |
| CVE-2024-39612 | MEDIUM | 5.5 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
| CVE-2024-38386 | HIGH | 7.8 | 0.2% | Sep 2, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now