2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29723 | CRITICAL | 9.8 | 0.4% | Aug 29, 2024 | SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to ret... |
| CVE-2024-7857 | MEDIUM | 6.5 | 0.5% | Aug 29, 2024 | The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter... |
| CVE-2024-45436 | HIGH | 7.5 | 2.6% | Aug 29, 2024 | extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent direct... |
| CVE-2024-45435 | CRITICAL | 9.8 | 0.6% | Aug 29, 2024 | Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function. |
| CVE-2024-41918 | MEDIUM | 6.1 | 0.3% | Aug 29, 2024 | 'Rakuten Ichiba App' for Android 12.4.0 and earlier and 'Rakuten Ichiba App' for iOS 11.7.0 and earlier are vulnerable t... |
| CVE-2024-8250 | MEDIUM | 5.5 | 0.3% | Aug 29, 2024 | NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or... |
| CVE-2024-45233 | CRITICAL | 9.8 | 0.4% | Aug 29, 2024 | An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can dir... |
| CVE-2024-45232 | MEDIUM | 5.3 | 0.3% | Aug 29, 2024 | An issue was discovered in powermail extension through 12.3.5 for TYPO3. It fails to validate the mail parameter of the ... |
| CVE-2024-8198 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the ... |
| CVE-2024-8194 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2024-8193 | HIGH | 8.8 | 0.4% | Aug 28, 2024 | Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the ... |
| CVE-2024-45059 | HIGH | 8.8 | 0.7% | Aug 28, 2024 | i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators... |
| CVE-2024-45058 | HIGH | 8.1 | 1.4% | Aug 28, 2024 | i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators... |
| CVE-2024-45057 | MEDIUM | 6.1 | 0.3% | Aug 28, 2024 | i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators... |
| CVE-2024-45048 | MEDIUM | 6.5 | 0.6% | Aug 28, 2024 | PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypas... |
| CVE-2024-45046 | MEDIUM | 5.4 | 0.4% | Aug 28, 2024 | PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In affected versions `\PhpOffice\PhpSpre... |
| CVE-2024-45054 | MEDIUM | 6.7 | 0.3% | Aug 28, 2024 | Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resource... |
| CVE-2024-45043 | MEDIUM | 5.3 | 0.5% | Aug 28, 2024 | The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream mess... |
| CVE-2024-44760 | HIGH | 7.5 | 0.5% | Aug 28, 2024 | Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0... |
| CVE-2024-43805 | MEDIUM | 6.1 | 0.4% | Aug 28, 2024 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit... |
| CVE-2024-42793 | HIGH | 8 | 0.2% | Aug 28, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted requ... |
| CVE-2024-34195 | CRITICAL | 9.8 | 0.9% | Aug 28, 2024 | TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server pro... |
| CVE-2024-44761 | CRITICAL | 9.8 | 1.1% | Aug 28, 2024 | An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted ... |
| CVE-2024-44915 | MEDIUM | 5.5 | 0.3% | Aug 28, 2024 | An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a... |
| CVE-2024-44914 | MEDIUM | 5.5 | 0.3% | Aug 28, 2024 | An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now