2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43926 | MEDIUM | 6.1 | 0.3% | Aug 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Beaver ... |
| CVE-2024-45056 | MEDIUM | 5.9 | 0.4% | Aug 29, 2024 | zksolc is a Solidity compiler for ZKsync. All LLVM versions since 2015 fold `(xor (shl 1, x), -1)` to `(rotl ~1, x)` if ... |
| CVE-2024-45045 | MEDIUM | 6.1 | 0.3% | Aug 29, 2024 | Collabora Online is a collaborative online office suite based on LibreOffice technology. In the mobile (Android/iOS) dev... |
| CVE-2024-44919 | MEDIUM | 5.4 | 0.3% | Aug 29, 2024 | A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute ar... |
| CVE-2024-43804 | HIGH | 8.8 | 2.5% | Aug 29, 2024 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerabi... |
| CVE-2024-41964 | HIGH | 8.1 | 0.4% | Aug 29, 2024 | Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users o... |
| CVE-2024-35133 | HIGH | 8.2 | 1.6% | Aug 29, 2024 | IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct ph... |
| CVE-2024-8255 | CRITICAL | 9.8 | 0.8% | Aug 29, 2024 | Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through... |
| CVE-2024-43965 | CRITICAL | 9.8 | 1.9% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGr... |
| CVE-2024-43957 | HIGH | 8.8 | 0.6% | Aug 29, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated ... |
| CVE-2024-43955 | HIGH | 7.5 | 0.6% | Aug 29, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows Fil... |
| CVE-2024-43954 | MEDIUM | 6.3 | 0.3% | Aug 29, 2024 | Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.T... |
| CVE-2024-43944 | LOW | 3.7 | 0.4% | Aug 29, 2024 | Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-com... |
| CVE-2024-43943 | HIGH | 8.8 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ... |
| CVE-2024-35118 | MEDIUM | 4.6 | 0.2% | Aug 29, 2024 | IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical a... |
| CVE-2024-8304 | MEDIUM | 4.9 | 0.6% | Aug 29, 2024 | A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an un... |
| CVE-2024-8303 | MEDIUM | 6.3 | 0.4% | Aug 29, 2024 | A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. T... |
| CVE-2024-43942 | HIGH | 8.8 | 0.4% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ... |
| CVE-2024-43941 | CRITICAL | 9.8 | 0.5% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Propovoice Propovo... |
| CVE-2024-43940 | MEDIUM | 6.5 | 0.4% | Aug 29, 2024 | Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constr... |
| CVE-2024-43939 | MEDIUM | 6.5 | 0.3% | Aug 29, 2024 | Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constr... |
| CVE-2024-43931 | CRITICAL | 9.8 | 0.5% | Aug 29, 2024 | Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch... |
| CVE-2024-43922 | CRITICAL | 9.8 | 0.4% | Aug 29, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injectio... |
| CVE-2024-43918 | CRITICAL | 9.8 | 1.5% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WBW Product Ta... |
| CVE-2024-43917 | CRITICAL | 9.8 | 21.8% | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders T... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now